Skip to main content

Splunk Attack Analyzer

recommended: allow
Operated by Splunk security

Splunk Attack Analyzer (formerly known as TwinWave), visits URLs submitted by customers using a headless Chrome browser. DOM (Document Object Model), HAR (HTTP Archive), and other relevant data from these visits are analyzed to determine if the page is hosting malicious content.

How to identify it

User-agent contains any of:

  • TwinWaveScanner

robots.txt

Well-behaved crawlers honor robots.txt. To control Splunk Attack Analyzer:

Allow full access

User-agent: TwinWaveScanner
Allow: /

Block entirely

User-agent: TwinWaveScanner
Disallow: /

Grey-area scrapers ignore robots.txt. Botscope enforces your policy at the edge or origin regardless — see how →

See Splunk Attack Analyzer on your own site

Botscope shows every bot and AI agent hitting your site — and lets you allow, challenge, or block each one. Observe first, enforce when you're ready.

Start free — connect in minutes