HTTP requests from commercial security scanner

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect high-volume HTTP traffic from known commercial security scanners or scanner-related callback domains.

Strategy

This rule monitors OCSF HTTP requests for user agents and URL or header values associated with commercial scanning products, grouped by @ocsf.src_endpoint.ip.

Triage and response

  • Determine if {{@ocsf.src_endpoint.ip}} belongs to an approved vendor scan or bug bounty program.
  • If not authorized, review targeted applications and whether sensitive paths or credentials were involved.