Attack tools
Someone tries to scan your site with a known attack tool.
What it is
Requests that announce themselves as a vulnerability scanner or attack tool.
- A request whose browser name is sqlmap or nikto
Why it matters
A scan is how most attacks start: the tool looks for a weakness, and a person follows up on what it finds.
When it stops a real visitor
If you or your web person ran the scan on purpose, mark the request as real, or switch to watch mode while the test runs.
What you will see most
- The request came from a known attack tool.
- The request named its software, and the name is a tool used to scan websites for weaknesses.
All 1 rules in this kind, as the rule set names them
For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.
- 913100Found User-Agent associated with security scanner