Skip to main content

Boteraser | Website and Server Security Solutions

watchTowr

Bot User-Agent: watchtowr

⚠️ Overview

watchTowr is a continuous security testing and attack surface management platform developed by the Singapore-based cybersecurity company watchTowr Labs, established in 2022 by former government and red-team operators. The company’s actively maintained scanner—often simply referred to as the watchTowr Scanner—is used for automated reconnaissance and vulnerability discovery, targeting both external and internal infrastructure. Its source code is not fully public, but snippets and configurations are published on their official GitHub repository (github.com/watchtowr) and blog (labs.watchtowr.com).

🔧 Technical Capabilities

The watchTowr scanner performs comprehensive attack surface mapping by enumerating subdomains, open ports, SSL certificates, and cloud assets. It actively probes for vulnerabilities in web applications, APIs, and network services, including known CVEs such as CVE-2023-4966 (Citrix Bleed) and CVE-2024-1709 (ConnectWise ScreenConnect). The tool uses a modular engine that can execute custom payloads, simulate lateral movement, and validate exploit chains. It also scrapes public data sources like Shodan, Censys, and certificate transparency logs to identify exposed assets. Behavioral profiling is a key feature: the scanner attempts to mimic human browsing patterns to evade basic rate limits and WAFs, though its User-Agent strings are intentionally static and identifiable.

📜 History & Notable Incidents

watchTowr has gained notoriety for responsibly disclosing critical vulnerabilities in high-profile vendors, including the Citrix NetScaler vulnerability CVE-2023-4966 (CVSS 9.8) which allowed session hijacking, and the JetBrains TeamCity CVE-2023-42793 authentication bypass. In 2024, their scanner was observed actively targeting unpatched instances of CVE-2024-27198 (JetBrains TeamCity again) and CVE-2024-6387 (OpenSSH regreSSHion). The company’s research blog (labs.watchtowr.com) documents these findings and often provides proof-of-concept code, making the scanner a persistent threat to organizations that do not keep up with patching.

🔍 Detection Indicators

The watchTowr scanner is identifiable by its default User-Agent string: “watchTowr” or variations like “watchTowr/1.0”. It also frequently uses the HTTP header “X-Forwarded-For” with randomized IPs. Traffic patterns include rapid sequential requests to common endpoints (e.g., /wp-admin, /api/v1, /.git/config) with short inter-request intervals (50–200 ms). In some cases, the scanner leaves a custom “X-watchTowr” response header during certain probes. Log entries from watchTowr's own GitHub confirm these fingerprints, and security vendors like CrowdStrike and Palo Alto have published signatures for them.

☠️ Risk & Impact

If unblocked, the watchTowr scanner can fully enumerate an organization’s external attack surface and identify exploitable vulnerabilities, leading to potential data breaches, ransomware deployment, or lateral movement. Because the tool validates exploits automatically, a successful scan can directly enable attackers to compromise systems without additional manual effort. The scanner’s ability to discover forgotten or unpatched assets significantly increases the risk of exposure for any internet-connected infrastructure.

🛡️ Mitigation

The watchTowr scanner is blocked immediately on detection because its sole purpose is to map and compromise systems, and it has been used both by legitimate researchers (with permission) and by malicious actors who repurpose its open-source components. Blocking its known User-Agents and traffic patterns at the network edge (WAF, IPS, or firewall) prevents reconnaissance and potential exploitation by adversarial users of the tool.

⚠️

Your Site May Be Hemorrhaging Revenue to Bots

Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.