Transparency

Network Telescope runs continuous, non-intrusive observation of the public internet for threat intelligence, measurements & metrics. Probes are easy to identify, easy to block & global exclusion is one request away.

What you'll see.

If our probes reach your logs, here is what the traffic is and why it is there. All probes are read-only by design. Across every probe class, payloads are benign and read-only. We never send malicious traffic, never POST, never attempt authentication, and never engage in any behaviour that could degrade the operation or security of a service.

Web probes.

HTTP & HTTPS GET requests against registered domains, domain names from newly issued certificates in Certificate Transparency logs, and newly registered domains. We also probe for the presence of standard endpoints and files such as robots.txt and ads.txt, and record their published responses.

Every request carries a fixed User-Agent identifying the scanner and a contact address:

Mozilla/5.0 (compatible; NetworkTelescope/1.0; +https://scanner.networktelescope.com; contact@networktelescope.com)

Name resolution.

Mass reverse-DNS (PTR) sweeps across the routable IPv4 space, plus forward queries against every registered domain name.

We also perform authoritative nameserver validation (checking NS records, glue, and serial consistency across delegated servers) and longitudinal stability measurements that re-resolve a sampled set of domains over time to characterise resolver behaviour and zone churn.

Active probing.

TCP SYN scans across IPv4 measure service counts and response behaviour on a broad set of ports. The same pipeline accelerates when a CVE lands so we can estimate the population of internet-exposed hosts running affected software. Connections do not progress past the SYN / SYN-ACK exchange unless a service banner is being collected.

UDP probes target protocols of measurement interest (DNS, NTP, SNMP, IKE, and similar) with a single well-formed query per host. Payloads are standard protocol requests, never crafted to elicit amplification.

ICMP, traceroute, and MTR measurements characterise path reachability, latency, and routing behaviour from a small set of measurement vantage points.

What we see.

Outside of active probing, we operate sensors that capture what reaches us unsolicited.

Honeypots.

Decoy services deployed across protocols record every attempted authentication, exploit, and post-exploitation action that touches them. Captured payloads, credentials, and tooling feed our threat-intelligence dataset and inform the CVE-driven scanning pipeline.

We also operate DNS honeypots that observe noise and spoofed traffic directed at our resolvers, characterising amplification probes, reflection abuse, and cache-poisoning attempts in the wild.

Network telescope.

A portion of undisclosed size of unused IP space is monitored continuously, capturing the unsolicited background radiation of the internet: misconfigured devices, opportunistic scanning, backscatter from spoofed traffic, worm and botnet activity, and the long tail of unattributed packets.

Compliance.

How our probes attribute themselves, and how we keep peer infrastructure out of our collection set.

Probe Attributions

Our probe attribution conforms to RFC 9511, the IETF specification for identification of internet measurement probes. Every scanner in our fleet serves the disclosure file /.well-known/probing.txt on port 80 from its own source IP, and the canonical copy is hosted at this domain over HTTPS.

Noise reduction.

To keep cross-research noise out of our dataset, every network registered in abuse.ch SinkDB is filtered before collection. The list is refreshed continuously so newly listed researchers are excluded without manual coordination.

We also pre-emptively exclude certain ASNs, domains, and address ranges from active scanning based on internal criteria, including networks belonging to universities, government and military operators, and other sensitive constituencies.

Remove your network.

If your network is not already covered by our SinkDB filter, email optout@networktelescope.com or use the form below. Requests are honoured globally within 72 hours.