Chisel
74 addresses running exposed Chisel tunnel endpoints — 62 still listed, 12 archived. Observed from 2026-08-29.
Detection packs
Rules for the 62 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.
About
An open-source tunnelling tool that carries TCP and UDP over HTTP, secured with SSH. It is published for network operators and used as readily for pivoting inside networks somebody has already broken into — the same transport that crosses a firewall legitimately is what makes it useful after a breach. What was observed here is a reachable chisel server, NOT what passed through it: the fingerprint a legitimate deployment emits is the same one, so this page records an exposed listener and claims nothing about the traffic or the operator's intent. Recently first observed in AS55933 on 2026-09-12 (1 host); AS209883 on 2026-09-09 (1 host) — networks this family had not appeared in before, as seen by this archive.
Ports
Addresses
Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.
Listed in error?
These pages are generated from automated scanning and are publicly available. Write to support@publicmosaic.com — see abuse & takedown, or opt-out to exclude a network range from scanning.