Tanod Monitor exposure scanner
This page describes our defensive exposure scanning: what it checks, where it comes from, and how to opt out. We only ever scan an asset whose owner has proven control of it through this service.
What we check
- A TCP connect scan of about 277 common service ports (7, 19, 20, 21, 22, 23, 25, 26, 37, 43, 49, 53, 70, 79, 80, 81, 82, 83, 84, 85, 88, 102, 110, 111, 113, 119, 123, 135, 137, 139, 143, 161, 179, 199, 389, 427, 443, 444, 445, 465, and 237 more).
- A passive banner read on open service ports (we send nothing first), the HTTP title and Server header, and the presented TLS certificate (subject, issuer, expiry, SANs).
- One benign UDP probe each to DNS (53), NTP (123) and SNMP (161) to detect an open resolver, an open NTP server or a device answering an unauthenticated SNMP read. No amplification requests (no DNS ANY, no NTP monlist).
- Passive RouterOS version detection mapped to MikroTik's public security advisories.
There is no exploitation, no password guessing, no vulnerability payloads and no brute force. The SNMP check is a single read-only query with the default community and is standard for exposure scanners.
Where scans come from
Scans originate from this service's published source address. HTTP probes carry the User-Agent
TanodMonitor-Scanner (+https://tanod.dev/monitor/scanner). Scans run at a deliberately low rate.
Opt out
We never scan an address unless its owner verified control of it here. If you still want a range excluded, ask us to add it to our opt-out list and it will never be scanned, even if someone later tries to verify it.
Plans
Free: 1 verified asset, weekly. Pro: 16 assets, daily.