l9scan
l9scan is the scanner used by LeakIX, a public attack-surface and leak indexing service. It probes internet-facing hosts to surface exposed services, misconfigurations, and leaked data.
At a glance
- Operator: l9scan
- Type: Security
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
l9scan publishes nothing Centinel can check a source against, so a match reports the name and leaves the source unconfirmed. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Security.