FlowIQ
FlowIQ is the scanning component of FlowIQ Labs, a commercial internet-wide service that probes publicly routable IPv4 addresses across common service ports rather than crawling sites by link. On web ports it issues a standard GET / request plus a follow-up fetch of /favicon.ico and records the response banner, TLS and public certificate metadata, and geolocation, and the operator states it does not attempt authentication, submit forms or credentials, or attempt exploitation. The operator publishes no IP ranges and no reverse DNS hostnames for verification, offering instead an IP or CIDR opt-out form and an abuse address at admin@flowiq-labs.com. Note that the operator documents its user agent as FlowIQLabsBot/1.0 while the traffic observed here identifies as FlowIQ/1.0, so this token may cover an undocumented variant or an imitator.
At a glance
- Operator: FlowIQ Labs
- Type: Security
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
FlowIQ publishes nothing Centinel can check a source against, so a match reports the name and leaves the source unconfirmed. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Security.