Modat — the scanner that publishes its list and actually sticks to it
by shop owners for shop owners.
How the PARC feed for Modat came about: an attack-surface scanner by Modat B.V. (NL) with its own ASN. Modat publishes an official IP list — and this time it is complete and fully FCrDNS-verifiable. 186 IPs.
Modat is an internet-wide attack-surface / asset-discovery scanner by Modat B.V. (Netherlands, own ASN MODAT-01). Not an SEO tool. Modat behaves well: fixed IPs, descriptive reverse DNS, and an official, published IP list. Unlike some other “official” feeds, here it is complete and fully FCrDNS-verifiable: 35 CIDRs = 186 IPs. Part of our PARC Security feed.
modat.json — view feed Modat — official list →
The official list — and why it holds up this time
Modat publishes its scan IPs at scanner.modat.io/ipv4.txt — 35 CIDR blocks (186 addresses). With ONYPHE we learned that “official” lists are often incomplete. Not here: we held the list against our CINS blacklist — CINS captured 107 actively scanning Modat IPs, and every single one sits inside the official list. Not one scanner outside it. So the list is complete and taken as-is.
Triple-verified
23.111.14.183 → l602.scanner.modat.io → 23.111.14.183 ✓
- Official list: scanner.modat.io/ipv4.txt
- Reverse DNS: all 186 → *.modat.io (pattern lNNN.scanner.modat.io)
- FCrDNS: 186 of 186 confirmed (forward record points back to the same IP) — 100%
This is our gold standard: a published list, bidirectionally confirmed, plus an own ASN (MODAT-01, Modat B.V.) — no rented cloud camouflage like Stretchoid or Infrawatch.
Who is behind it
Modat B.V. is a Dutch attack-surface intelligence company — it scans the internet for exposed assets, operating from its own infrastructure (ASN MODAT-01, plus some Leaseweb-SG/NewVM). Transparent operation: fixed reverse names, published list, identifiable.
