If you've seen EchelonGraphBot in your logs, here's exactly what it does and how to block it
EchelonGraphBot is a web crawler operated by EchelonGraph, Inc. that scans public websites to check configurations such as HTTPS enforcement, certificate expiration, TLS versions, security headers, cookie flags, and redirects. It visits a large number of third-party hosts approximately once per day, respecting robots.txt and rate limits. Operators can opt out via a DNS TXT record or robots.txt. The bot's activity is transparent and publicly documented, with no evidence of malicious intent or exploitation. The operator offers to adjust probing frequency upon request and honors opt-out requests.
AI Analysis
Technical Summary
EchelonGraphBot is a crawler that probes public websites to gather data on security configurations and site setup. It respects robots.txt directives and rate limits, making at most one request per host per day unless otherwise requested by the domain operator. The bot's activity is logged and publicly visible via the EchelonGraph Radar platform. Operators can opt out using a DNS TXT record or robots.txt. The bot does not perform aggressive scanning and backs off on HTTP 403 responses. The operator is transparent about the bot's behavior and provides contact information for inquiries or complaints.
Potential Impact
The bot performs non-intrusive scanning of public websites to collect security-related metadata. It does not exploit vulnerabilities or cause harm but may generate log entries and network traffic. There is no indication of malicious activity or active exploitation associated with this bot. Its presence in logs is informational and related to routine scanning.
Mitigation Recommendations
No urgent action is required. If the bot's activity is undesired, operators can opt out by adding a DNS TXT record or configuring robots.txt to disallow the bot. The operator respects these opt-out mechanisms and will cease probing accordingly. Contacting the operator can also result in adjustments to probing frequency.
If you've seen EchelonGraphBot in your logs, here's exactly what it does and how to block it
Description
EchelonGraphBot is a web crawler operated by EchelonGraph, Inc. that scans public websites to check configurations such as HTTPS enforcement, certificate expiration, TLS versions, security headers, cookie flags, and redirects. It visits a large number of third-party hosts approximately once per day, respecting robots.txt and rate limits. Operators can opt out via a DNS TXT record or robots.txt. The bot's activity is transparent and publicly documented, with no evidence of malicious intent or exploitation. The operator offers to adjust probing frequency upon request and honors opt-out requests.
Reddit Discussion
We run a crawler that checks how public websites are set up. Things like whether HTTPS is enforced, when the certificate expires, which TLS version is offered, what security headers are set, how cookies are flagged, and where redirects go.
If it has been hitting your servers, you probably want to know what it is. So we wrote the whole thing down on one page: echelongraph.io/bot It covers how often it visits a single host, how it handles robots.txt and Retry-After, which address it comes from, what it will never do, and how to opt out with a DNS record. No signup, no popup.
Two notes on the opt-out, since that is usually the first question. It is a DNS TXT record, so you do not need an account with us to use it. And robots.txt works the normal way if you would rather do it there.
The data it collects is also public at echelongraph.io/radar if you want to look up your own domain, or anyone else's. Free, no account.
Things that are not finished, so you hear it from us first:
- We say checks can run every 30 seconds. They actually land about once a minute. The scheduler does not honour the shorter setting yet.
- Checks stop a couple of minutes after you close the tab.
Happy to answer anything about the crawler's behaviour. If it has done something in your logs that the bot page does not explain, tell me and I will fix either the bot or the page.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
EchelonGraphBot is a crawler that probes public websites to gather data on security configurations and site setup. It respects robots.txt directives and rate limits, making at most one request per host per day unless otherwise requested by the domain operator. The bot's activity is logged and publicly visible via the EchelonGraph Radar platform. Operators can opt out using a DNS TXT record or robots.txt. The bot does not perform aggressive scanning and backs off on HTTP 403 responses. The operator is transparent about the bot's behavior and provides contact information for inquiries or complaints.
Potential Impact
The bot performs non-intrusive scanning of public websites to collect security-related metadata. It does not exploit vulnerabilities or cause harm but may generate log entries and network traffic. There is no indication of malicious activity or active exploitation associated with this bot. Its presence in logs is informational and related to routine scanning.
Defensive Guidance
No urgent action is required. If the bot's activity is undesired, operators can opt out by adding a DNS TXT record or configuring robots.txt to disallow the bot. The operator respects these opt-out mechanisms and will cease probing accordingly. Contacting the operator can also result in adjustments to probing frequency.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":22,"reasons":["external_link","non_newsworthy_keywords:how to","established_author","very_recent"],"isNewsworthy":true,"foundNonNewsworthy":["how to"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa7476655bf5e2cf54dfbab
Added to database: 09/14/2026, 01:01:26 UTC
Last enriched: 09/14/2026, 01:01:32 UTC
Last updated: 09/14/2026, 04:31:22 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.