Scanning Transparency
Source addresses and User-Agents let defenders recognize, investigate, allow, or block traffic from each Scan for Good assessment route.
Use the source addresses and HTTP identifiers below to recognize Scan for Good activity. Deep-dive source details are also confirmed directly with the participating organization before testing begins.
| Assessment route | Source IPs | HTTP identifier | Purpose |
|---|---|---|---|
| Continuous public attack-surface monitoring |
| User-AgentX-Wiz-RedAgent | Deterministic public attack-surface scanning and AI-powered assessment through Wiz Attack Surface Management and Wiz Red Agent. |
| Cyber Gemini deep dive | Provided during scope confirmation | Request headerProvided during scope confirmation | AI-powered black-box penetration testing of one explicitly authorized application. |
General product capabilities are documented in the public material for Wiz Attack Surface Management and Wiz Red Agent. A deep-dive assessment is restricted to the application, dates, accounts, and boundaries agreed directly with the organization.
Program-specific authorization and scope always take precedence over the general product descriptions. Public reachability alone is not authorization to test.
Email scanforgood@wiz.io with the destination hostname, source address, User-Agent, timestamp and timezone, and a small redacted request sample. Do not send credentials, personal data, or sensitive production content by ordinary email.