Skip to main content

If you've seen EchelonGraphBot in your logs, here's exactly what it does and how to block it

0
Medium
Published: 09/14/2026 (09/14/2026, 00:14:40 UTC)
Source: Reddit NetSec

Description

EchelonGraphBot is a web crawler operated by EchelonGraph, Inc. that scans public websites to check configurations such as HTTPS enforcement, certificate expiration, TLS versions, security headers, cookie flags, and redirects. It visits a large number of third-party hosts approximately once per day, respecting robots.txt and rate limits. Operators can opt out via a DNS TXT record or robots.txt. The bot's activity is transparent and publicly documented, with no evidence of malicious intent or exploitation. The operator offers to adjust probing frequency upon request and honors opt-out requests.

Reddit Discussion

r/netsec·posted by u/Foreign_Score_4021
00

We run a crawler that checks how public websites are set up. Things like whether HTTPS is enforced, when the certificate expires, which TLS version is offered, what security headers are set, how cookies are flagged, and where redirects go.

If it has been hitting your servers, you probably want to know what it is. So we wrote the whole thing down on one page: echelongraph.io/bot It covers how often it visits a single host, how it handles robots.txt and Retry-After, which address it comes from, what it will never do, and how to opt out with a DNS record. No signup, no popup.

Two notes on the opt-out, since that is usually the first question. It is a DNS TXT record, so you do not need an account with us to use it. And robots.txt works the normal way if you would rather do it there.

The data it collects is also public at echelongraph.io/radar if you want to look up your own domain, or anyone else's. Free, no account.

Things that are not finished, so you hear it from us first:

- We say checks can run every 30 seconds. They actually land about once a minute. The scheduler does not honour the shorter setting yet.

- Checks stop a couple of minutes after you close the tab.

Happy to answer anything about the crawler's behaviour. If it has done something in your logs that the bot page does not explain, tell me and I will fix either the bot or the page.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 01:01:32 UTC

Technical Analysis

EchelonGraphBot is a crawler that probes public websites to gather data on security configurations and site setup. It respects robots.txt directives and rate limits, making at most one request per host per day unless otherwise requested by the domain operator. The bot's activity is logged and publicly visible via the EchelonGraph Radar platform. Operators can opt out using a DNS TXT record or robots.txt. The bot does not perform aggressive scanning and backs off on HTTP 403 responses. The operator is transparent about the bot's behavior and provides contact information for inquiries or complaints.

Potential Impact

The bot performs non-intrusive scanning of public websites to collect security-related metadata. It does not exploit vulnerabilities or cause harm but may generate log entries and network traffic. There is no indication of malicious activity or active exploitation associated with this bot. Its presence in logs is informational and related to routine scanning.

Defensive Guidance

No urgent action is required. If the bot's activity is undesired, operators can opt out by adding a DNS TXT record or configuring robots.txt to disallow the bot. The operator respects these opt-out mechanisms and will cease probing accordingly. Contacting the operator can also result in adjustments to probing frequency.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":22,"reasons":["external_link","non_newsworthy_keywords:how to","established_author","very_recent"],"isNewsworthy":true,"foundNonNewsworthy":["how to"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa7476655bf5e2cf54dfbab

Added to database: 09/14/2026, 01:01:26 UTC

Last enriched: 09/14/2026, 01:01:32 UTC

Last updated: 09/14/2026, 04:31:22 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses