Scanning Transparency

How to identify Scan for Good traffic

Source addresses and User-Agents let defenders recognize, investigate, allow, or block traffic from each Scan for Good assessment route.

Status
Current identifiers
Last updated
August 27, 2026
Questions or urgent stop
scanforgood@wiz.io

Traffic registry

Use the source addresses and HTTP identifiers below to recognize Scan for Good activity. Deep-dive source details are also confirmed directly with the participating organization before testing begins.

Scan for Good traffic identifiers
Assessment routeSource IPsHTTP identifierPurpose
Continuous public attack-surface monitoring
  • 52.203.79.240
  • 54.147.52.191
  • 174.129.249.241
User-AgentX-Wiz-RedAgentDeterministic public attack-surface scanning and AI-powered assessment through Wiz Attack Surface Management and Wiz Red Agent.
Cyber Gemini deep diveProvided during scope confirmationRequest headerProvided during scope confirmationAI-powered black-box penetration testing of one explicitly authorized application.

What the traffic does

General product capabilities are documented in the public material for Wiz Attack Surface Management and Wiz Red Agent. A deep-dive assessment is restricted to the application, dates, accounts, and boundaries agreed directly with the organization.

Program-specific authorization and scope always take precedence over the general product descriptions. Public reachability alone is not authorization to test.

Report unexpected traffic

Email scanforgood@wiz.io with the destination hostname, source address, User-Agent, timestamp and timezone, and a small redacted request sample. Do not send credentials, personal data, or sensitive production content by ordinary email.