Scan Header
The Chariot HTTP header and chariot- User-Agent Guard puts on scan traffic so you can allowlist it, plus the OOB callback host.
Scan Header is the unique identifier Guard includes on scan traffic for your account. The card reads Unique identifier included in all scans. Click the value to copy Chariot: <identifier> to the clipboard. Guard confirms with Scan header copied to clipboard.
What scan traffic carries
HTTP scan requests can carry two markers built from your identifier:
Nuclei vulnerability templates send both. Other web scanners send the same markers.
To allowlist Guard scans in a web application firewall, intrusion detection system, or SIEM, match either marker:
- The
Chariotheader is present with your identifier. - The
User-Agentstarts withchariot-.
These markers identify traffic only. Anyone can send the same header or User-Agent, so do not use them to skip authentication or authorization.
Out-of-band callbacks
Nuclei tests for blind vulnerability classes (SSRF, XXE, blind XSS, SMTP injection) embed callback URLs on:
oob.guard.praetorian.com
If a target is vulnerable, it makes an outbound DNS or HTTP request to that host. Blocking egress to *.oob.guard.praetorian.com does not fail the scan, but Guard cannot confirm those blind findings.
Who can change it
No one. The identifier is fixed for your account. You can only copy it.