Corrections
The scanner withdraws a detection when its evidence turns out not to support the listings it produced: either the detection matched software other than the one it named, or it identified the software correctly but that identification is not evidence of malicious use. This archive then stops publishing those listings. This page records that it happened and how much — by family, basis and day. It names no address, port, certificate or host name: withdrawing a listing means not republishing it.
Of the 1186 withdrawn listings: 1056 matched software other than the one named; 130 identified a tool correctly without evidence of malicious use.
By family
Withdrawn listings against every listing this archive has held under the same label. A family is linked where its page still exists.
Each withdrawal
Newest first, by the day the scanner withdrew the detection, and by the basis on which it did.
| Withdrawn | Family | Basis | Listings | Addresses |
|---|---|---|---|---|
| 2026-09-26recorded here 2026-09-27 | Ligolo-ng | tool identified, not evidence of misuse | 108 | 99 |
| 2026-09-26recorded here 2026-09-27 | Chisel | tool identified, not evidence of misuse | 2 | 2 |
| 2026-09-25recorded here 2026-09-27 | Chisel | embedded in other software | 1026 | 1026 |
| 2026-09-25recorded here 2026-09-27 | Chisel | tool identified, not evidence of misuse | 20 | 20 |
| 2026-08-31recorded here 2026-09-26 | NanoCore | echo taken for an answer | 19 | 16 |
| 2026-08-31recorded here 2026-09-27 | Chisel | echo taken for an answer | 11 | 11 |
What each basis means
Matched other software.
- echo taken for an answer — The probe accepted a reply that only repeated its own request, so services that echo whatever they are sent were listed.
- embedded in other software — Other software builds in the same component and answered the probe exactly as the named software would.
- structure shared with other software — The certificate or message structure the detection keyed on is shared by other, ordinary software.
- matched other software — The detection matched software other than the one it named.
Identified the tool, not evidence of misuse.
- tool identified, not evidence of misuse — The software was identified correctly, but it is also used legitimately, and identifying it is not evidence of malicious use.
not classified — recorded before this archive kept a basis for each withdrawal, and not yet given one. The withdrawal is in effect all the same.
What is counted, and what is not
A listing here is one address and port, from the first time the scanner reported it. It is counted when the scanner has withdrawn the detection that produced it and this archive has recorded that withdrawal against it. Recording waits for the scanner's operators to say which listings a withdrawal covered, which has so far taken from a day or two to several weeks; until then those listings are still published here as archived. Once it is recorded, within minutes the listing appears on no host page, family page, directory, sitemap, detection pack or API response, and an address with nothing else left to publish answers 410 Gone. Nothing is deleted: the archive keeps the record, flagged, and publishes this count instead.
Not counted: listings withdrawn at the request of someone responsible for an address (abuse & takedown) or inside a verified excluded range (opt-out) — those are requests about an address, not findings about a detection.
Withdrawn share is the withdrawn listings divided by every listing this archive has held under that family label. It counts both kinds of withdrawal: a tool identified correctly and withdrawn because that is not evidence of misuse is counted beside a detection that matched other software, so it is not a rate of misidentification. It says how much of what was published under one label was taken back, and nothing about any other label, or about this one from now on.
The scanner's own notes on each withdrawal — which signature, which listings — are kept in this archive's private record and are not published, because they identify hosts. How a listing is established, and the classes of withdrawal found so far, are set out in methodology. The same counts are published as JSON at /api/corrections.json.