Uploaded August 2026 | Updated September 2026, 1 hour ago
Yukiko Endo (NICT, JP), Masato Jingu (NICT, JP), Masaki Kubo (NICT, JP)
Security teams routinely waste time investigating benign scans from services such as Censys, Shodan, ZoomEye, and other survey‑scanners. However, there has been no comprehensive, openly available source that identifies which organizations are scanning the global IPv4 space and from which IP addresses.
We operate a large darknet monitoring network and developed a real‑time methodology to classify survey‑scanner traffic and distinguish it from malicious activity. Using this approach, we have identified more than 75 active scanning organizations worldwide.
Our team publishes a quarterly, publicly accessible list of survey‑scanner IP addresses and organizations on GitHub, enabling SOC analysts, incident responders, and network defenders to reduce false investigations and focus on actual threats. We also demonstrate how we integrate this list into our own security operations and quantify its operational impact.
Because many survey‑scanners provide ASM‑related commercial services based on their scanning activity, we additionally highlight behavioral differences among scanners to help practitioners better interpret and validate ASM outputs. Drawing on years of large‑scale darknet monitoring and continuous IP intelligence publishing, we provide practical insights that the community can immediately use to improve alert triage and threat‑hunting accuracy.
---
Yukiko Endo is a Senior Technical Researcher at the Cyber Threat Analysis Office, National Institute of Information and Communications Technology (NICT) in Japan, where she actively works on darknet monitoring, internet-wide scanning analysis, and threat intelligence research. Before joining NICT, she worked in both Japan and Germany on research and product development in the field of Identity and Access Management. Her broader interests include IoT security, Internet-wide measurement, and the collection and analysis of threat intelligence data.
Masato Jingu is an analyst at the Cyber Threat Analysis Office of the National Institute of Information and Communications Technology (NICT). He also serves as a member of NICT-CSIRT, where he is primarily responsible for the analysis of a livenet. Prior to joining NICT, he held positions in the private sector, where he was engaged in cybersecurity incident response as well as research and development activities.
Masaki Kubo serves as Director of the Cyber Threat Analysis Office at NICT. His responsibilities extend to both the internal security operation and a darknet monitoring research project known as 'NICTER'. Prior to joining NICT, He was a manager of JPCERT coordination center, focusing on the analysis and coordination of vulnerabilities and advocating for a secure coding initiative.
Yukiko Endo (NICT, JP), Masato Jingu (NICT, JP), Masaki Kubo (NICT, JP)
Security teams routinely waste time investigating benign scans from services such as Censys, Shodan, ZoomEye, and other survey‑scanners. However, there has been no comprehensive, openly available source that identifies which organizations are scanning the global IPv4 space and from which IP addresses.
We operate a large darknet monitoring network and developed a real‑time methodology to classify survey‑scanner traffic and distinguish it from malicious activity. Using this approach, we have identified more than 75 active scanning organizations worldwide.
Our team publishes a quarterly, publicly accessible list of survey‑scanner IP addresses and organizations on GitHub, enabling SOC analysts, incident responders, and network defenders to reduce false investigations and focus on actual threats. We also demonstrate how we integrate this list into our own security operations and quantify its operational impact.
Because many survey‑scanners provide ASM‑related commercial services based on their scanning activity, we additionally highlight behavioral differences among scanners to help practitioners better interpret and validate ASM outputs. Drawing on years of large‑scale darknet monitoring and continuous IP intelligence publishing, we provide practical insights that the community can immediately use to improve alert triage and threat‑hunting accuracy.
---
Yukiko Endo is a Senior Technical Researcher at the Cyber Threat Analysis Office, National Institute of Information and Communications Technology (NICT) in Japan, where she actively works on darknet monitoring, internet-wide scanning analysis, and threat intelligence research. Before joining NICT, she worked in both Japan and Germany on research and product development in the field of Identity and Access Management. Her broader interests include IoT security, Internet-wide measurement, and the collection and analysis of threat intelligence data.
Masato Jingu is an analyst at the Cyber Threat Analysis Office of the National Institute of Information and Communications Technology (NICT). He also serves as a member of NICT-CSIRT, where he is primarily responsible for the analysis of a livenet. Prior to joining NICT, he held positions in the private sector, where he was engaged in cybersecurity incident response as well as research and development activities.
Masaki Kubo serves as Director of the Cyber Threat Analysis Office at NICT. His responsibilities extend to both the internal security operation and a darknet monitoring research project known as 'NICTER'. Prior to joining NICT, He was a manager of JPCERT coordination center, focusing on the analysis and coordination of vulnerabilities and advocating for a secure coding initiative.










