For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-92d.md. A documentation index is available at /llms.txt.

HTTP requests from security scanner

Goal

Detect HTTP scanning behavior from user agents associated with common open-source or offensive security tools.

Strategy

This rule monitors OCSF HTTP requests for tool-specific user agents and measures breadth of paths accessed, grouped by @ocsf.src_endpoint.ip.

Triage and response

  • Confirm authorized security assessments versus unexpected external scanning from {{@ocsf.src_endpoint.ip}}.
  • Prioritize review when many distinct paths return successful responses.