ELLIO Gets a Major Upgrade in Its Recon & Mass Exploitation Intelligence
Today, we’re releasing a major set of improvements to ELLIO Reconnaissance and Mass Exploitation Intelligence.
The goal is straightforward: turn millions of individual observations into a clear picture of how an IP performs reconnaissance, discovers vulnerabilities, and attempts exploitation, including what it targets, how its behavior changes, and what other activity is connected to it.
This release gives you 3 times more behavioral detections and tags, deeper HTTP and port activity analysis, a new query engine for custom searches, a more detailed geographic footprint, and richer observation context from the ELLIO Deception Network.
1. Know whether an IP is scanning, probing, or exploiting
Extended analytics intelligence enables you to see where an IP sits in the reconnaissance to exploitation lifecycle and distinguish broad Internet scanning from activity that indicates target discovery, vulnerability discovery, or active exploitation. Instead of seeing an IP simply as a “scanner,” you can identify whether it is:
- Discovering targets and exposed attack surfaces
- Fingerprinting applications, devices, IoT systems, or security tools
- Probing for specific vulnerabilities or sensitive resources
- Attempting web, device, or code execution exploitation
- Attempting unauthorized access
- Deploying malware or establishing C2
- Performing security research or other trusted activity
You also see how these behaviors relate to each other, for example, whether an IP moves from fingerprinting and target discovery into vulnerability probing and exploitation.
Why it matters: an IP that scans your infrastructure is not automatically a threat. The ability to distinguish broad scanning from targeted reconnaissance and exploitation helps you identify which activity represents a meaningful attack progression and deserves investigation.

2. Turn thousands of HTTP requests into recognizable attack patterns
Large scale HTTP scanning can generate thousands of requests that are difficult to interpret individually. The new HTTP path normalization and HTTP grouping turns this activity into recognizable patterns, making it easier to understand what an IP is trying to discover or exploit.
You can identify:
- Which applications and technologies are being targeted
- Which paths and endpoints are being probed
- Which HTTP methods are being used
- Whether activity is broad reconnaissance or focused probing
- Whether behavior is changing or escalating toward exploitation
Dedicated search for HTTP paths and User Agents also gives you direct hunting pivots. For example, you can find IPs probing a newly exploited endpoint or identify other infrastructure using the same scanner.
Why it matters: HTTP exploitation campaigns often generate large volumes of repetitive requests. Grouping and normalization let you focus on the attack pattern itself, making it easier to recognize targeted probing and connect different IPs using the same tooling.

3. Pivot from an exploiting IP to related attacker infrastructure
Reconnaissance and mass exploitation rarely originate from a single IP address. The new ELLIO Query Engine makes it possible to search across millions of live context items and pivot between IPs, connections, and behavioral signals as needed.
The ELLIO Query Engine enables flexible analysis across all recorded data, including User-Agents, HTTP paths, TCP and TLS fingerprints, tags, ASN numbers, and the newly introduced HTTP normalization engine.
A particularly useful example is the query http.path.normalized: "/.aws/config". It can identify IP addresses that attempted to bypass a WAF or otherwise obfuscate their requests—for example, by using an encoded variant such as /%2f%2eaws%2fconfig.
By normalizing HTTP paths before analysis, ELLIO makes these variations easier to detect and correlate, helping security teams uncover related activity that might otherwise be missed.
4. Use IP observation history to see the bigger picture
Knowing whether an IP has been observed once or repeatedly can help you put an individual event into context. The ELLIO platform now provides this observation history, showing how often an IP has been observed by the ELLIO Deception Network and what types of activity were associated with those observations, such as reconnaissance or exploitation attempts.
This gives you additional context when investigating an unfamiliar IP or correlating related activity. A repeated history may warrant looking more closely at an indicator than a single, isolated observation.

5. See when an IP changes its recon target
ELLIO Port Intelligence now let you compare an IP’s current port activity with its 91 day history, spot newly observed ports, visualize its port space, and quickly search for specific ports.
Why it matters: a change in the ports an IP targets can reveal a change in its reconnaissance objective. Historical context helps distinguish established scanning behavior from a new focus that may indicate preparation for exploitation.
Act before attackers get in
ELLIO gives you visibility into what happens before compromise: who is discovering attack surfaces, probing vulnerabilities, exploiting systems, and what infrastructure is behind that activity. Prevent compromise before it creates incident response costs, business disruption, and recovery work.
Start exploring ELLIO Intelligence here: https://platform.ellio.tech
Written by
Jana Tom is the Founder of ELLIO, a cybersecurity research lab focused on understanding and defense against reconnaissance and mass exploitation activity on the internet.