GreyNoise: Knowing the difference between benign and malicious internet scans
When Shodan launched, people freaked out. “How dare you scan my device connected to the public internet,” freaker-outers griped. Yet Shodan is a benign scanner and useful for many defensive tasks. (Maybe don’t connect those devices to the internet? Just sayin’.) Shodan is by no means the only scanner sweeping the entire IPv4 address space, all 4.2 (and a bit) billion of ’em. So do Censys, Sonar and ShadowServer. Like Shodan, they scan noisily from fixed IP subnets and announce their intentions.