Scan Header

The Chariot HTTP header and chariot- User-Agent Guard puts on scan traffic so you can allowlist it, plus the OOB callback host.

Scan Header is the unique identifier Guard includes on scan traffic for your account. The card reads Unique identifier included in all scans. Click the value to copy Chariot: <identifier> to the clipboard. Guard confirms with Scan header copied to clipboard.

What scan traffic carries

HTTP scan requests can carry two markers built from your identifier:

Marker

Format

Chariot header

Chariot: <identifier>

User-Agent

chariot-<identifier>

Nuclei vulnerability templates send both. Other web scanners send the same markers.

To allowlist Guard scans in a web application firewall, intrusion detection system, or SIEM, match either marker:

  • The Chariot header is present with your identifier.
  • The User-Agent starts with chariot-.

These markers identify traffic only. Anyone can send the same header or User-Agent, so do not use them to skip authentication or authorization.

Out-of-band callbacks

Nuclei tests for blind vulnerability classes (SSRF, XXE, blind XSS, SMTP injection) embed callback URLs on:

oob.guard.praetorian.com

If a target is vulnerable, it makes an outbound DNS or HTTP request to that host. Blocking egress to *.oob.guard.praetorian.com does not fail the scan, but Guard cannot confirm those blind findings.

Who can change it

No one. The identifier is fixed for your account. You can only copy it.