Canonir scanning
Canonir is an external attack surface management service. If you are seeing requests from canonir-scanner, a Canonir customer has engaged us to assess an internet-facing estate, and we believe the system you operate is part of it.
What the traffic is
Our assessments are non-intrusive. We observe what a system publishes to the internet: we open connections, complete TLS handshakes, request pages and read the responses, as any standard client would. We do not attempt to exploit anything, we do not attempt to authenticate, we do not guess credentials, and we take no action intended to degrade a system's performance or availability.
Some assessments are configured by the customer to render pages in a full browser, request paths that disclose a software version, or capture a screenshot. In a log this appears as a brief series of ordinary page loads, including the images and scripts a browser requires. Those requests go only to the system under assessment: anything hosted elsewhere, such as a CDN, a font service or an analytics endpoint, is blocked before the request leaves our infrastructure. An operator whose service is merely embedded by an assessed page will therefore not see our traffic at all.
Requests are rate-limited. If our traffic is nevertheless causing operational problems, the contact below is the fastest way to stop it, and no customer relationship is required to use it.
How to recognize us
- User-Agent
- canonir-scanner/1.0 (+https://www.canonir.com/scanning)
- robots.txt token
- canonir-scanner
Canonir does not treat general robots.txt directives as limits on an assessment a customer has authorized. A User-agent: * rule addresses uninvited crawlers, and an authorized assessment is not one. To exclude particular paths, address us directly: a User-agent: canonir-scanner group in your robots.txt is honored on every assessment, at all times, and cannot be overridden by any setting or by the customer who commissioned the scan. Where such a group narrows an assessment, the report tells the customer which rules applied and how many requests they stopped. It does not tell them who added the rules. The same is true if you ask us to stop by email: the customer sees that a target was withheld, and not who asked. This behavior is implemented and covered by tests, not a statement of intent.
Source addresses
Canonir assessments originate from a small set of fixed addresses. Publication of the current list is in preparation. Until it appears here, verify our traffic by the User-Agent above, or contact us and we will confirm whether an address is ours.
How to ask us to stop
To request that Canonir not assess a system you operate, email us the domain or address range concerned.
- The request applies to every Canonir customer, and stops assessments already in progress
- A single request blocks the system across our platform, for existing and future customers alike, and cancels any assessment currently running against it. It is not necessary to establish which customer commissioned the scan, and the request does not need to be repeated.
- No account and no proof of control required
- A request is actioned whether or not the requester holds an account with us, and no evidence of control over the system is asked for. Verification is required to restore assessment, not to stop it.
- We will not confirm whether the system was being assessed
- The reply to a request is the same whether or not the system was under assessment, because confirmation would disclose the existence of an engagement. That standard reply is stated here so it is not read as evasion.
- A block is reversible
- If a request was made in error, assessment can be restored by whoever controls the system, upon demonstrating that control.