Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
ethomason.com is the personal security research blog of Ethan Thomason. The crawled content indicates that the author is based in Northern California and also runs CedarTech, with expertise in Ignition/SCADA and OT/ICS security. The site mainly documents threat intelligence research, including Cowrie SSH honeypots, the OT-focused honeypot project otpot, malware analysis, internet scanner behavior, SCADA gateway identification, and observations of exposed industrial control systems. It should therefore be viewed as a research-oriented intelligence source rather than a conventional cybersecurity product or managed protection platform.
In terms of protection value, the site provides observation and analysis: for example, identifying exposed Ignition gateway versions, documenting SSH credential spraying, analyzing attackers using SSH direct-tcpip forwarding to access ip-who.com, tracking cryptocurrency-mining malware such as Panchan and Redtail, and observing scanning behavior from Censys, Shodan, and similar services. As for deployment, the articles only state that the author runs Cowrie and OT honeypots independently; there are no user-deployable agents, SaaS offerings, sensors, or enterprise platforms. There is also no productized description of management, alerting, or integration capabilities. Although the articles reference external sources such as AbuseIPDB, GreyNoise, VirusTotal, Shodan, and Censys, these appear to be research aids rather than formal API integrations.
The crawled content does not mention subscriptions, pricing, free or paid plans, enterprise support, SLAs, payment methods, or compliance certifications. As such, it should not be treated as a security service that can be directly purchased. Organizations that need SOC alerts, attack surface monitoring, compliance reporting, or vendor support should still choose a mature platform.
Its strengths are that the content is based on real honeypot and network assessment data, with a particular focus on OT/ICS scenarios. It can help defenders understand how exposed industrial assets are scanned, subjected to credential spraying, infected with miners, or abused for tunnel forwarding. The articles contain substantial technical detail and are useful for threat hunting and security training. The downside is that it is clearly a personal blog, lacking productized capabilities, Chinese-language support, service commitments, and structured threat intelligence delivery.
It is suitable reading for OT security researchers, industrial control system integrators, blue teams, and threat intelligence analysts. It is not suitable as a standalone protection system. The source text does not provide information on accessibility from China, so its status is unknown. If alternatives are needed, consider GreyNoise, Shodan, Censys, AbuseIPDB, or commercial OT-focused threat intelligence and asset exposure management solutions.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on ethomason.com official site.
ethomason.com is an United States Security provider. TG4G tracks its product information, an overall rating of 5.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach ethomason.com directly.