This address performs authorized security testing.
The IP address you followed here belongs to Trident Security's managed vulnerability-scanning infrastructure. Traffic from it is authorized penetration testing and vulnerability scanning carried out for a Trident customer under a signed agreement, against systems that customer owns or controls.
It is not an attack, and it is not opportunistic scanning of the internet at large. Every scan is scoped in writing to a specific customer's own assets before it runs.
How to identify our traffic
Requests from this infrastructure are deliberately identifiable:
-
User-Agent contains
TridentSecurityScanner -
Every request carries an
X-Trident-Scan-Idheader with the scan's unique ID -
Reverse DNS on our egress addresses resolves to a
tridentsecurity.iohostname
You can filter or allowlist on any of the above.
If you are investigating traffic you have seen
Email contact@tridentsecurity.io and include whatever you have:
- the source IP address
- a timestamp with timezone
-
the
X-Trident-Scan-Idvalue, if it appears in your logs
We will confirm whether the traffic was one of our authorized engagements, normally within one business day.
Stopping testing against your systems
If you believe we are testing infrastructure that should not be in scope, say so in that same email and we will halt testing against the affected systems while we verify the authorization. We stop first and confirm afterwards.
For urgent matters, mark the subject line
URGENT — STOP SCAN.
Reporting a vulnerability in this host
Machine-readable contact details are published at /.well-known/security.txt per RFC 9116.