CyberConvoy Scout
CyberConvoy Scout is the internet-wide scanning platform of the security vendor CyberConvoy. It sweeps public IPv4 and IPv6 space with single SYN probes and lightweight banner grabs on ports 80, 443, 3389, 1080, 4153 and 1337, collecting service banners, HTTP response headers and TLS certificates to map internet-facing services for threat intelligence and defensive research. The operator publishes an RFC 9511 probing.txt, a self-service opt-out form, an abuse contact and four scanner IPv4 addresses plus one IPv6 /64. Its documentation claims the scanner IPs carry reverse DNS pointing back to cyberconvoy.co, but all four published addresses actually resolve to vultrusercontent.com hostnames, a shared hosting suffix, so no operator-controlled hostname exists to verify against.
At a glance
- Operator: CyberConvoy
- Type: Security
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
CyberConvoy Scout publishes nothing Centinel can check a source against, so a match reports the name and leaves the source unconfirmed. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Security.