Authorised security scanner
If traffic from one of the addresses below reached your infrastructure, it came from a security assessment that was authorised by the organisation responsible for that infrastructure.
Machine-readable: /ips.txt (one per line) · /ips.json. These are generated from the infrastructure that assigns them, so they are current rather than transcribed. If you allowlist by address, read one of those rather than this page.
-random-agent is explicitly disabledDiscovery — DNS, HTTP requests, certificates — runs against anything in an authorised scope. Port scanning and vulnerability checks are treated differently: they require a signed authorisation from the organisation that owns the systems and a separate, per-host decision to enable them. Both default to off. A scope being in the platform is not an instruction to scan it.
Contact your own security team first. The assessment is commissioned by your organisation, and they can tell you which engagement this is and whether it is in scope — faster than we can, because we will not discuss a client's engagement with a third party.
If you believe the traffic is not authorised, or you need it stopped immediately, email abuse@aevyrascan.com with the source address, the destination, and a timestamp with its timezone. We will identify the scan and stop it.
If it is authorised and you simply want quieter alerting, allowlist the addresses above in your detection rules rather than blocking them at the perimeter. Blocking produces a clean report of a closed door, which is the one outcome that helps nobody: your security team pays for an assessment and receives findings from a scanner that could not reach anything.