HTTP requests from security scanner

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Goal

Detect HTTP scanning behavior from user agents associated with common open-source or offensive security tools.

Strategy

This rule monitors OCSF HTTP requests for tool-specific user agents and measures breadth of paths accessed, grouped by @ocsf.src_endpoint.ip.

Triage and response

  • Confirm authorized security assessments versus unexpected external scanning from {{@ocsf.src_endpoint.ip}}.
  • Prioritize review when many distinct paths return successful responses.