Scan Attribution
How to use the Aurelius scan attribution skill to confirm whether scanning activity observed on your infrastructure originated from the Guard platform.
Scan Attribution
Security teams that receive alerts about scanning activity hitting their infrastructure can use Guard's scan attribution skill to determine definitively whether that activity originated from the Guard platform. The skill correlates a provided indicator against Guard's own scanning records and returns a confirmed or denied attribution with supporting evidence.
Overview
When a SIEM, IDS, WAF, or SOC alert surfaces unexpected scanning traffic, the scan attribution skill lets you ask Aurelius directly: "Was this the Guard platform?" Guard compares the indicator you supply against its internal scan records and responds with an authoritative, evidence-backed answer.
Supported Indicators
You can provide any of the following as an attribution indicator:
Combining multiple indicators (for example, an IP address together with a timestamp) will narrow the correlation and produce a more precise result.
How to Use the Skill
Locate the indicator in your alert source (SIEM event, IDS log, WAF log, or SOC ticket).
Open Aurelius in the Guard platform.
Submit a natural-language query that includes the indicator. For example:
- "Was the scan from 203.0.113.42 on June 10 at 14:32 UTC the Guard platform?"
- "Did Guard scan my infrastructure using this user-agent:
<string>?"
Aurelius returns one of two outcomes:
Interpreting Results
- A confirmed result includes the specific Guard scan records that match the indicator. Review the evidence to tie the activity back to a particular assessment or discovery job.
- A denied result means Guard has no record of the activity. The source of the scanning traffic should be investigated through other means.
- If the indicator is ambiguous or the timeframe is too broad, Aurelius may prompt you to supply additional context to narrow the correlation.
Use Cases
- Resolving SOC alerts triggered by Guard discovery or assessment scans before escalating to incident response.
- Providing evidence to internal stakeholders or third-party security operations teams that scanning activity is authorized and attributable to Guard.
- Reducing false-positive incident tickets generated by WAF or IDS rules that flag Guard's scanning infrastructure.
Support
If you receive an unexpected result or need help correlating a specific indicator, contact support@praetorian.com.