Skip to content

What it blocks

Attack tools

Someone tries to scan your site with a known attack tool.

What it is

Requests that announce themselves as a vulnerability scanner or attack tool.

  • A request whose browser name is sqlmap or nikto

Why it matters

A scan is how most attacks start: the tool looks for a weakness, and a person follows up on what it finds.

When it stops a real visitor

If you or your web person ran the scan on purpose, mark the request as real, or switch to watch mode while the test runs.

What you will see most

The request came from a known attack tool.
The request named its software, and the name is a tool used to scan websites for weaknesses.
All 1 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 913100Found User-Agent associated with security scanner