How Are You Blocking Open Source Reconnaissance Tools?
ID: 7345f6d2-7532-5baf-b5a8-965f808e8cb8
STIX ID: report--7345f6d2-7532-5baf-b5a8-965f808e8cb8
Feed Name: SOCRadar Blog
The report explains how benign internet-wide scanners (Shodan, Censys, ZoomEye, BinaryEdge, etc.) collect service and certificate metadata that both defenders and attackers can use, causing SOC alert noise because their activity resembles malicious reconnaissance. It describes the limitations of IP blocklists, the operational value of classifying scanner traffic rather than blindly blocking it, and recommends integrating continuously updated benign-scanner intelligence (such as SOCRadar Premium Feeds) into SIEM/XDR/NDR workflows to suppress false positives and improve visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
