Home › Blog

Article

NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)

Ninja Signal · field note

Read by Machines

We built a threat-intelligence platform for humans. Thirteen days of logs say almost no humans came. The machines did — and some of them were wearing masks.

ninja.ing · measured off our own edge logs · 19 Aug – 1 Sep 2026

Here is an uncomfortable thing to publish about your own product, so we may as well lead with it. Over thirteen days our estate — a graph-native threat-intel platform and a dozen sister apps — served 899,786 requests. We ran every one through a classifier that strips search crawlers, vulnerability scanners, our own monitors, and, ruthlessly, our own dashboards. What was left, when the noise burned off, was this:

2  genuine human visitors

899,786 requests → ~36K real content views → 6 owner IPs, 592 hosting/VPN, 2 residential humans. The single biggest "user" of the platform was me, polling my own dashboards.

You can read that as bleak. We read it as clarifying. Because when you filter for who actually pulled our pages, the audience turns out not to be absent at all. It's just not human.

total requests 899,786

crawlers + scanners 297,162

internal / monitors 85,698

scan-probes wearing browser UAs 186,998

owner dashboard polling 11,962

genuine residential humans 2

Who actually reads us

144,340 requests from 23 AI systems

Separate the AI crawlers from everything else and a different picture appears — a busy one. In the same window, 23 distinct AI agents hit the estate 144,340 times. Meta and Google between them accounted for over a hundred thousand requests, hammering our science-foresight pages. Anthropic's ClaudeBot fixated on a single search page and pulled it 2,304 times. These are verified — confirmed against each operator's own network.

Meta58,715

Google45,529

Ahrefs · SEO14,316

Anthropic7,414

Amazon1,023

OpenAI · GPTBot392

So the platform isn't unread. It's being ingested — indexed, trained on, folded into the models that will answer the next person who asks an AI about graph-native threat intelligence. That's a real distribution channel, and it's the one that's working.

The signal that wasn't there

Zero real-time user-fetches

There's one AI hit that matters more than all the training crawls: the user-fetch — when a human asks ChatGPT or Claude or Perplexity a question, and the assistant fetches your page live to answer it. That's the moment you become the answer. We looked hard for it.

We found zero genuine ones. Not one. Every request wearing a ChatGPT-User or Claude-User or Perplexity-User badge failed verification — because it hadn't come from OpenAI or Anthropic or Perplexity at all.

The masks

A botnet dressed as the assistants

Here's where a traffic report turns into a threat-intel finding. Those fake "user-fetches" all traced back to the same cluster: a spread of Google Cloud and Hostodo IPs cycling through AI-crawler user-agents — ChatGPT one minute, Claude the next, Amazonbot after that — and pointing every one of them at the same targets: /login, /.env.old, /.git/HEAD. It's reconnaissance wearing a costume, and the costume is the point: an Amazonbot or ChatGPT-User string sails through the WAF rules that would flag a raw scanner.

source IPhitsimpersonatingreal network34.182.165.28754Amazonbot · ChatGPT-User · ClaudeBotGoogle LLC136.67.28.143738Amazonbot · ChatGPT-User · GPTBotGoogle LLC34.16.220.62723Amazonbot · ChatGPT-User · OAI-SearchBotGoogle LLC34.13.224.135542Claude-User · Amazonbot · GPTBotGoogle LLC35.196.160.4533OAI-SearchBot · Claude-User · PerplexityGoogle LLC

Thirty-three source IPs, every genuine-looking "someone asked an AI about us" event, fake. Fake-AI-bot reconnaissance is an emerging tactic precisely because it's cheap and it works — most log pipelines allow-list the AI crawlers by name and never check whether the name is telling the truth.

We built for an audience of humans. The machines came instead — and a few of them were only pretending to be the good machines.

What we did about it

We turned the logs into a lens

The classifier that produced these numbers isn't a one-off script anymore. It runs on the platform, refreshes twice a day off our edge logs, and it's public — no login:

The AI Crawler Observatory — live per-operator telemetry, verified crawls versus impersonators, at ninjasignal.ninja/crawlers.

A blockable impersonator feed — the fake-AI-bot IPs as a plain-text list you can drop into a WAF or null-route, at /intel/crawlers/impersonators.txt. It's deterministic and verified by reverse-org lookup, so it won't blackhole the real ClaudeBot along with the fakes.

No model in the loop, nothing asserted that wasn't measured. Which is the same way we build everything else here — the ML surface ships with a scorecard where every number is a temporal-holdout backtest, and the one prediction thesis we most wanted to be true, we tested and reported as disproven.

Why publish this

The honest version is the interesting one

A launch post is supposed to tell you the numbers are up and to the right. Ours says two humans read the site in a fortnight. But the same logs say the labs that build the world's AI are ingesting us daily, that nobody has yet asked an assistant about us live, and that criminals find our login pages worth impersonating a chatbot to reach.

If your platform is being read mostly by machines, the useful questions change. Are you legible to them — cleanly, quotably, honestly? Can you tell the real ones from the fakes? We decided the answer to both should be something we can point at. So we pointed at it.

Every figure here was read out of our own Caddy access logs on 1 September 2026. The full breakdown, refreshed live, is at the Observatory.

Ninja Signal — graph-native threat intelligence, part of the ninja.ing sovereign security cloud.

AI Crawler ObservatoryImpersonator feedninjasignal.ninjaninja.ing

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing