Authorised security scanner

AevyraScan

If traffic from one of the addresses below reached your infrastructure, it came from a security assessment that was authorised by the organisation responsible for that infrastructure.

scanner
AevyraScan/1.0
operator
Aevyra
purpose
external attack surface assessment
user-agent
Mozilla/5.0 (compatible; AevyraScan/1.0; +https://aevyrascan.com/)
abuse
abuse@aevyrascan.com
updated
2026-09-03

Addresses it scans from

Machine-readable: /ips.txt (one per line) · /ips.json. These are generated from the infrastructure that assigns them, so they are current rather than transcribed. If you allowlist by address, read one of those rather than this page.

What it does, and what it does not

It does

  • Resolve DNS records for names in the authorised scope
  • Make ordinary HTTP and HTTPS requests, and record the responses
  • Complete TLS handshakes to read certificate details
  • Capture a screenshot of pages, as an ordinary visitor would see them
  • Attempt TCP connections to ports, and run vulnerability checks — only where that was separately authorised

It does not

  • Attempt to gain access, escalate privilege or move laterally
  • Guess, spray or brute-force credentials
  • Send traffic intended to degrade or deny service
  • Disguise itself — the user-agent above is sent on every request, and -random-agent is explicitly disabled
  • Scan anything on an internal or private network

Why some of it is passive and some is not

Discovery — DNS, HTTP requests, certificates — runs against anything in an authorised scope. Port scanning and vulnerability checks are treated differently: they require a signed authorisation from the organisation that owns the systems and a separate, per-host decision to enable them. Both default to off. A scope being in the platform is not an instruction to scan it.

If you want it to stop

Contact your own security team first. The assessment is commissioned by your organisation, and they can tell you which engagement this is and whether it is in scope — faster than we can, because we will not discuss a client's engagement with a third party.

If you believe the traffic is not authorised, or you need it stopped immediately, email abuse@aevyrascan.com with the source address, the destination, and a timestamp with its timezone. We will identify the scan and stop it.

If it is authorised and you simply want quieter alerting, allowlist the addresses above in your detection rules rather than blocking them at the perimeter. Blocking produces a clean report of a closed door, which is the one outcome that helps nobody: your security team pays for an assessment and receives findings from a scanner that could not reach anything.