<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to highlight a Pen-Tester's IP? in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217026#M27310</link>
    <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21530"&gt;@chris_v&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is an excellent suggestion! I only have one issue here, and that is that you might block other valid requests in the /24 subnet. How do you deal with this?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2023 18:34:28 GMT</pubDate>
    <dc:creator>AntonioSousa</dc:creator>
    <dc:date>2023-07-05T18:34:28Z</dc:date>
    <item>
      <title>How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216929#M27297</link>
      <description>&lt;P&gt;I have had several cases where pen-testing has disrupted monitoring, creating problems that have to be diagnosed and traced back to the user. I have compiled a series of ways of dealing with these issues, including Request Attributes for client IP, MDAs that track those users, maintenance windows, and other tricks. I had the idea to convert some of this data into Problems, but then again, I want to reduce them, not make some more. I have also been considering using custom annotations to highlight these cases in the UI, but have not yet implemented anything.&lt;/P&gt;
&lt;P&gt;I believe a lot of you have dealt with this issue. What type of tricks do you have to deal with allowed pen-testers?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 07:11:31 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216929#M27297</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-07-05T07:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216932#M27298</link>
      <description>&lt;P&gt;Sounds like I do most of that, the only thing I'll add is.&amp;nbsp; I use web request naming (a global rule) to rename all requests with the testers IP (a server side request attribute), as (in my case) "Nessus Scan", and then mute that request.&lt;BR /&gt;&lt;BR /&gt;So the testing does not interfere with any real users data going to the normally named web requests, and being muted doesn't raise problems. &lt;BR /&gt;&lt;BR /&gt;added benefit of not filling Dynatraces database with high cardinality data that's full of random characters and invalid paths etc.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 05:42:35 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216932#M27298</guid>
      <dc:creator>chris_v</dc:creator>
      <dc:date>2023-07-05T05:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216933#M27299</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Combination of specific HTTP headers and request attributes. It means, what you see &lt;A title="in the documentation" href="https://www.dynatrace.com/support/help/shortlink/load-testing-process#tag-test-requests-and-push-custom-events" target="_blank" rel="noopener"&gt;in the documentation&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 06:49:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/216933#M27299</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2023-07-05T06:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217026#M27310</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21530"&gt;@chris_v&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is an excellent suggestion! I only have one issue here, and that is that you might block other valid requests in the /24 subnet. How do you deal with this?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 18:34:28 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217026#M27310</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-07-05T18:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217051#M27315</link>
      <description>&lt;P&gt;In this use case the permitted testing is run internally, so we can use the full unmasked private IPs, we're only masking public IPs.&lt;/P&gt;
&lt;P&gt;The request attribute rule currently has 4 data source rules each a unique IP.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/58682"&gt;@AntonPineiro&lt;/a&gt; suggests some header info. that may be a usable option depending if the testing tools make themselves known that way. Nessus/Tenable from what I've seen often - but not always - includes an identifiable mark in the requests made (e.g. it'll be in the URL and/or user agent). and of course if you can control the requests being made, you can ensure a header is added for identification.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 00:04:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217051#M27315</guid>
      <dc:creator>chris_v</dc:creator>
      <dc:date>2023-07-06T00:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217052#M27316</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":clapping_hands:"&gt;👏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 00:44:33 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217052#M27316</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2023-07-06T00:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to highlight a Pen-Tester's IP?</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217071#M27317</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21530"&gt;@chris_v&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In my case they are masquerading as real browsers, because of browser rules being implemented, but it's another good idea.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 07:49:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-highlight-a-Pen-Tester-s-IP/m-p/217071#M27317</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-07-06T07:49:16Z</dc:date>
    </item>
  </channel>
</rss>

