CensysInspect

Bot User-Agent: censysinspect

⚠️ Overview

CensysInspect is the user-agent string associated with the automated scanning engine of Censys, a cybersecurity company founded by researchers from the University of Michigan (including Zakir Durumeric, J. Alex Halderman, and others) that specializes in internet-wide reconnaissance and vulnerability discovery. The tool is part of Censys’s commercial and academic platform, which continuously probes the entire IPv4 address space to map exposed services, certificates, and software versions. While Censys is a legitimate research and enterprise security tool, its scanning bots—including CensysInspect—are routinely blocked by web application operators because they conduct unauthorized, high-frequency probing that can indicate pre-attack reconnaissance or violate terms of service.

🔧 Technical Capabilities

CensysInspect performs comprehensive port scans across TCP/UDP, focusing on common web ports (80, 443, 8080, 8443) and hundreds of others. It executes HTTP/HTTPS requests to banner-grab service headers, TLS certificates, and application fingerprints, using the CensysInspect/1.0 user agent (variants exist). The scanner leverages the ZMap and ZGrab toolkits—both open-source projects developed by the same team—to achieve sub‑hour scan cycles across the entire public internet. It identifies vulnerabilities such as weak TLS configurations, expired certificates, default credentials on IoT devices, and unpatched software by comparing discovered fingerprints against Censys’s threat intelligence database. The bot does not perform exploitation but systematically collects data used for attack surface analysis, making it a precursor to targeted attacks if the data is misused.

📜 History & Notable Incidents

Censys was launched in 2017 after its predecessor, the Internet-Wide Scan Data Repository (SCADA), demonstrated large-scale scanning capabilities. The CensysInspect bot has been observed scanning millions of IPs hourly; in 2023, university networks reported blocks due to aggressive scanning that triggered DDoS-like load on edge devices. Censys itself has documented that its scanners originate from IP ranges like 162.142.125.0/24 and 167.94.138.0/24 (publicly listed on Censys’s documentation). Notably, Censys data has been used in academic papers (e.g., measuring HTTPS adoption) but also abused by malicious actors who purchase access to its datasets for target identification.

🔍 Detection Indicators

The primary indicator is the HTTP User-Agent string: CensysInspect/1.0 (other variations include Censys/1.0 or CensysInspect/2.0). Behavioral fingerprints include rapid sequential IP scanning from a single source, repeated requests to non‑standard ports, and TLS handshakes without completing full HTTP exchanges. Observed source IPs are predominantly from the United States and Europe, listed in Censys’s published ASN (AS398324). Traffic patterns show bursts of thousands of SYN packets per second, often targeting a single web server within seconds.

☠️ Risk & Impact

Although CensysInspect does not attempt exploitation, its reconnaissance enables attackers to map attack surfaces—exposing misconfigured endpoints, outdated software, and weak encryption—without the target’s consent. This intelligence can be leveraged for targeted phishing, credential stuffing, or vulnerability exploitation. Additionally, the high-volume scanning can saturate network bandwidth and trigger false positives in intrusion detection systems, leading to operational overhead for security teams.

🛡️ Mitigation

We immediately block all traffic from known Censys IP ranges (e.g., 162.142.125.0/24, 167.94.138.0/24) and deny any request containing the CensysInspect user agent string. This stops unauthorized reconnaissance at the perimeter, preventing potential follow‑on attacks and reducing unnecessary load on application infrastructure.

🛡️

Stop Bots. Save Bandwidth. Protect Revenue.

Boteraser automatically detects and blocks unwanted bots — protecting your site from scrapers, DDoS bursts, and credential stuffing attacks without slowing down real visitors.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.