This page exists for anyone who has noticed a connection from ichnos and wants to know what it is, why it happened, and how to stop it.
| Protocol | Port |
|---|---|
| https | 443 |
| http | 80 |
Nothing beyond a normal protocol handshake is attempted - the same negotiation a web browser performs when it loads a page.
Server
banner, page title, redirect location.No application content, credentials, or session data is collected or retained.
Discovery of new hosts runs continuously at roughly one request per second (ZMap's own native rate limit), in short windows every 15 minutes - not a sustained flood, and a given address is essentially never sampled twice by discovery in any practical timeframe. Hosts already known to respond get a separate, single re-check once a day (a "refresh" pass) to detect changes, not repeated probing. See ZMap's Scanning Best Practices, which this project follows for target selection, rate limiting, and exclusion handling.
Abuse or questions: abuse@opteryx.app. To stop being scanned, use the opt-out form - it takes effect before the next scheduled scan and does not require a reason.
No fixed retention period is currently enforced; historical records are retained for research purposes. Opting out stops future collection for the excluded address - it does not retroactively delete records already published.
Internet measurement and research, not commercial reconnaissance or targeting. Source code, design rationale, and exclusion logic are public: https://github.com/mabel-dev/ichnos.
Machine-readable: security.txt · scanner.txt