The Pirates of Inspiration.

Roughly 14 years ago, an anonymous researcher published a paper and a dataset titled Internet Census of 2012. The data was collected by the Carna botnet — a worm that quietly compromised and hijacked around 420,000 embedded devices left exposed on the public internet with default or no credentials. Working in concert, the bots probed literally the entire internet: a near-complete port scan of the IPv4 space (roughly 4 billion addresses), ICMP ping data, reverse DNS records, service banners, and SYN scans across common ports.

Carna botnet visualisation: 24-hour relative utilisation of the IPv4 address space, June–October 2012
Carna botnet, 2012 — relative IPv4 utilisation across a 24-hour cycle. Source: Wikipedia — Carna botnet.

The researcher behind it was anonymous and never identified. After publishing the paper and releasing the 9 TB torrent dataset, the botnet was shut down and went dark. The paper is signed only as "Carna" — no follow-up work, no claim of credit, and no public attribution since.

A mystery researcher of the internet whose census sparked not only controversy but a wave of curiosity and intrigue across the security community. It was a fascinating piece of work — illegal, brilliant, and done anonymously out of curiosity, not malice or for personal recognition.

That is the story that sparked our interest, but that was 14 years ago, and boy has the internet grown into an unrecognisable monolith since. We took it as a challenge and asked ourselves the obvious next question: could a census of that scale be built today, legitimately, attributably, and kept current against an internet that no longer sits still?

That question is what we have spent the last decade answering — an eagle-eye view of the open internet's vast ocean of intelligence, made sense of on behalf of the people who need to scope something specific within it.

A decade of quiet building.

What followed was years of unglamorous work. We studied the protocols that hold the global edge together — routing, naming, certificate issuance, transport. We read every relevant RFC and most of the irrelevant ones. We learned the operational rhythms of the regional internet registries, the trust politics of the certificate transparency ecosystem, the legal shape of mass measurement in a dozen jurisdictions, and the cultural norms of the network operator community that ultimately decides who is welcome to scan and who is not.

We absorbed the open-data canon that grew up after Carna — the academic measurement literature, the Internet Topology Atlas, RouteViews and RIPE Atlas, the certificate transparency logs, the Open-INTEL project, the work that came out of CAIDA and ANT Lab. We were not the first to take the open internet seriously as a research subject. We wanted to be the most rigorous.

Slowly, an infrastructure emerged. We acquired our own address space and stood up our own scanning fabric. We built ingest for every public certificate transparency log. We deployed a global mesh of authoritative and passive DNS sensors, a distributed honeypot network, and a peering footprint that lets us watch the global routing table in real time. We negotiated partnerships with operators willing to share what they could legally share. We learned how to handle stealer logs, breach data, and other sensitive corpora responsibly, with provenance preserved end to end.

The wild west of the internet.

The modern internet is a chorus of packet cowboys. Port scanners sweeping IPv4 around the clock, opportunistic CVE exploitation attempts the moment a vulnerability lands, compromised hosts spraying brute-force SSH attempts, residential proxies tunnelling abuse through home connections, and an ever-growing fleet of AI agents crawling the open web for training data and grounding. There is already an enormous amount of noise on the wire before anyone with good intent ever starts probing.

That noise has a real cost: any new traffic at scale risks being lumped in with it. Even a careful, attributable measurement programme can be mislabelled as malicious by automated block-list operators, security vendors, and ISPs who classify first and read the User-Agent later (if at all). Internet-scale observation done badly does not just embarrass the operator — it actively poisons the well for every other legitimate researcher trying to do the work.

Probing the entire planet for intelligence is harder than the surface description makes it sound, and we learned every part of it the hard way. The systems involved are vast, the operators running them are particular, and the laws that govern measurement vary by jurisdiction in ways that take real work to understand. None of it forgives shortcuts, and none of it tolerates anonymity for long.

What we do, in short: continuous, non-intrusive observation of the public internet for threat intelligence, measurement, and longitudinal research. We operate transparently, with full attribution on every probe and a public record of what we collect and why, all documented on our transparency page. Network operators who would rather not be observed can opt out at any time, and we honour those requests globally without question.

We operate alongside a small community of legitimate measurement firms and academic researchers who work to similar standards, and we believe internet-scale observation is best done in plain sight — by parties who can be held to account for what they do. That is the only version of this work we are willing to do.

What we do with it.

At its core, the work is measurement. We study the internet end to end, take metrics on what is running, where, in what configuration, and how that surface is changing over time. From those measurements we extract intelligence: the shape of an attack landscape, the infrastructure behind a fraud campaign, the population affected by a fresh CVE, the long arc of how a protocol or a threat actor is evolving year over year.

Why we do it: by mapping what is exposed, mis-configured, and out-of-date on the public internet, we get a near-real-time picture of where threat actors are already looking and what they are likely to compromise next. We track running services, software versions, and response fingerprints so that when a new CVE drops we can put a defensible number on its blast radius — how many hosts, in which networks, and in which jurisdictions are actually affected — rather than guessing. The same dataset feeds longitudinal measurements of how the internet itself is changing, from protocol adoption curves to the slow drift of the public addressing surface.

We operate alongside government agencies, law-enforcement units working fraud and cyber-crime investigations, intelligence services with attribution requirements, and a small roster of private clients who need ground truth that vendor telemetry cannot provide. Every deliverable is backed by raw evidence we collected ourselves, with the provenance preserved end to end.

Think of Network Telescope as a digital telescope. The internet is the sky; we keep the optics calibrated, the dataset current, and the pointing precise. When you need to look at a specific actor, region, protocol, vulnerability, or campaign, we can train the instrument on it and tell you, in defensible terms, what is actually there. We study the internet, research it, and make sense of it on your behalf.