Splunk Attack Analyzer
Splunk Attack Analyzer (formerly known as TwinWave), visits URLs submitted by customers using a headless Chrome browser. DOM (Document Object Model), HAR (HTTP Archive), and other relevant data from these visits are analyzed to determine if the page is hosting malicious content.
At a glance
- Operator: Splunk
- Type: Security
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
Splunk Attack Analyzer publishes nothing Centinel can check a source against, so a match reports the name and leaves the source unconfirmed. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Security.