{"uid":"cap_vD3_tVyWYF9AsWgQyXft1","slug":"polyform-scanner-ip-blocklist-08a9ecb3","name":"Polyform Scanner IP Blocklist","description":"Recent IPs caught probing Polyform's honeypot paths (credential/vuln scanners) — Polyform's own first-party telemetry, not a repackaged public list. Returns up to 500 most-recent scanner IPs with first-seen. For blocklists and threat research. JSON.","url":"https://api.polyform.org/v1/threat/scanners","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"count":200,"scanners":[{"ip":"45.134.26.5","probe":"/.env","firstSeen":"2026-08-25T04:00:00Z"}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_zi9xEeyduCaF8RCl1MemJ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns up to 500 of the most recent IPs caught probing Polyform's honeypot paths (credential and vulnerability scanners), with first-seen timestamps.","exampleAgentPrompt":"Pull the latest list of IPs that have been caught scanning Polyform's honeypot paths — I want to use them to update my blocklist with the most recent credential and vulnerability scanner IPs.","exampleUseCases":[{"title":"Automated firewall blocklist refresh","prompt":"Fetch the latest scanner IPs from Polyform's honeypot telemetry so I can push them into our firewall blocklist and block any IPs actively probing for .env files or known vuln paths."},{"title":"Threat research on active credential scanners","prompt":"I'm doing research on IPs currently scanning for exposed credentials and config files — can you pull Polyform's honeypot scanner list so I can analyze which probes are most common and when they were first seen?"},{"title":"Security dashboard IP enrichment","prompt":"Get me the current list of scanner IPs from Polyform's honeypot, including the probe paths they hit and first-seen dates, so I can cross-reference them against our access logs for any matches."}],"resultDescription":"A JSON object containing a count of returned IPs and an array of scanner records, each with the scanner's IP address, the honeypot path it probed (e.g. /.env), and the ISO 8601 first-seen timestamp. Returns up to 500 of the most recent scanner IPs.","failureModes":["Payment not received or insufficient USDC — returns 402 Payment Required","Service temporarily unavailable — returns 5xx error","Rate limiting or quota exceeded — returns 429 Too Many Requests","Empty result set if no recent scanner activity has been recorded"],"whenToPreferThis":"Choose this endpoint when you need fresh, first-party honeypot telemetry on active credential and vulnerability scanners rather than a repackaged public blocklist. It is especially valuable when you want IPs that have been caught probing real infrastructure (/.env, vuln paths) with a first-seen timestamp, for use in dynamic blocklists, firewall rules, or threat research. Prefer this over generic IP reputation feeds when honeypot-sourced, single-provider freshness is a priority.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:40:18.439Z","isFirstParty":false}