Information about automated requests from Ryan Gerstenkorn
Want the requests to stop? If a request from my scanner reached a system it should not have, is causing a problem, or you would simply prefer not to receive it, email bb@ryanjarv.sh.
Include the affected domain or host and, if available, the request timestamp, source IP, and relevant headers.
A system you operate received an automated request from security research tooling that I run. I use this tooling to identify publicly reachable services and investigate potential security issues through bug bounty and vulnerability disclosure programs.
I only intend to test systems covered by programs that invite this research. Scope and ownership can be unclear or change over time, so if I got it wrong, please let me know and I will correct it.
Most activity consists of DNS lookups, connection checks, and HTTP requests that observe how a public service responds. The tooling is designed not to create, change, or delete data, and it follows the applicable program's rules and configured rate limits. Potential findings are reported through the relevant program rather than published by the scanner.
I'm Ryan Gerstenkorn, an independent security researcher focused on cloud and web security. You can verify my identity and see examples of my work through the profiles below.