Scan Attribution

How to use the Aurelius scan attribution skill to confirm whether scanning activity observed on your infrastructure originated from the Guard platform.

Scan Attribution

Security teams that receive alerts about scanning activity hitting their infrastructure can use Guard's scan attribution skill to determine definitively whether that activity originated from the Guard platform. The skill correlates a provided indicator against Guard's own scanning records and returns a confirmed or denied attribution with supporting evidence.


Overview

When a SIEM, IDS, WAF, or SOC alert surfaces unexpected scanning traffic, the scan attribution skill lets you ask Aurelius directly: "Was this the Guard platform?" Guard compares the indicator you supply against its internal scan records and responds with an authoritative, evidence-backed answer.


Supported Indicators

You can provide any of the following as an attribution indicator:

Indicator Type

Example

IP address

203.0.113.42

User-agent string

Mozilla/5.0 (compatible; GuardScanner/1.0)

Timestamp

2025-06-10T14:32:00Z

Hostname

scanner.guard.praetorian.com

Combining multiple indicators (for example, an IP address together with a timestamp) will narrow the correlation and produce a more precise result.


How to Use the Skill

  1. Locate the indicator in your alert source (SIEM event, IDS log, WAF log, or SOC ticket).

  2. Open Aurelius in the Guard platform.

  3. Submit a natural-language query that includes the indicator. For example:

    • "Was the scan from 203.0.113.42 on June 10 at 14:32 UTC the Guard platform?"
    • "Did Guard scan my infrastructure using this user-agent: <string>?"
  4. Aurelius returns one of two outcomes:

    Outcome

    Meaning

    Confirmed

    The indicator matches Guard's scan records. Supporting evidence (scan job details, timestamps, originating asset scope) is included in the response.

    Denied

    The indicator does not match any Guard scanning activity within the correlatable timeframe.


Interpreting Results

  • A confirmed result includes the specific Guard scan records that match the indicator. Review the evidence to tie the activity back to a particular assessment or discovery job.
  • A denied result means Guard has no record of the activity. The source of the scanning traffic should be investigated through other means.
  • If the indicator is ambiguous or the timeframe is too broad, Aurelius may prompt you to supply additional context to narrow the correlation.

Use Cases

  • Resolving SOC alerts triggered by Guard discovery or assessment scans before escalating to incident response.
  • Providing evidence to internal stakeholders or third-party security operations teams that scanning activity is authorized and attributable to Guard.
  • Reducing false-positive incident tickets generated by WAF or IDS rules that flag Guard's scanning infrastructure.

Support

If you receive an unexpected result or need help correlating a specific indicator, contact support@praetorian.com.