Entities
Addresses
A single address: which operator runs it, how it was discovered, and what else sits on its network.
The most common entry point. Shows the verdict, the observations behind it, the surrounding network, and where to go next.
Two discovery channels
An address reaches the dataset by one of two independent channels. The distinction bears on how an answer should be weighted.
| Channel | What happened | Method |
|---|---|---|
| Probing | We connected through the provider and observed this exit | probe |
| Scanning | The host answered on a port VPN infrastructure uses | scan |
Probing is the stronger claim: traffic was routed through the service and egressed here. Scanning establishes that infrastructure is present without proving egress. Both are evidence; only probing produces a time series.
An address neither channel reached is still answered when any of our sources — probing, the enriched snapshot, scan certificates — knows at least one address of its announced prefix. The answer then carries method: "interpolated", names the prefix in network, gives the prefix’s providers and weights, and a confidence from the share of the prefix observed. See Methods and evidence.
Who held the address
Where several providers used an address, every source contributes the days it saw each one — a day our probing exited through it, the enriched snapshot’s last sighting, each scan run that found the operator’s certificate — and each day counts half as much for every 30 days before today. Days, not events: probing one provider more often does not win it the address. The leader holds the largest share; where the most recent sighting belongs to someone else, the page says most recently seen as that provider, because a handover takes weeks to show in the shares.
History, week by week
Every address page has a History: each week since probing began, Monday to Sunday, with the strongest evidence that week holds and the providers behind it — for an address one provider held as much as for one that changed hands. First and last seen are per provider there, not only for the address as a whole.
| Evidence | That week |
|---|---|
| Probe | Our probing exited through the address. Shares count days seen, recent days more |
| Scan | A scan run found a VPN operator’s certificate on it |
| Interpolated | Neither, but probing reached other addresses of its announced prefix that week. Shares count the prefix’s addresses per provider that week |
| — | Nothing. Consecutive empty weeks are folded into one row |
Choose the window on the strip of weeks — drag it, or pick 4, 13 or 52 weeks — and filter by evidence; the choices combine. A week is the smallest unit. An address we never observed still shows its network, prefix and country from our own tables.
Sharing
sharing.iocValue states whether the address identifies the actor or only the service. On a commercial VPN exit shared by thousands of users, the address is a weak indicator regardless of attribution confidence. This is stated explicitly rather than left to inference.