Overview
Splunk Attack Analyzer is an AI training crawler from Splunk used for AI model training, dataset discovery, and collection of public web content for model-development pipelines.
Its primary user-agent pattern is TwinWaveScanner.
Splunk Attack Analyzer is Unverified at the identity-evidence level. The listed identity remains useful for detection, but this record does not currently contain authoritative evidence sufficient to authenticate the identity claim.
Robots.txt behavior is not currently confirmed.
Splunk Attack Analyzer can usually be allowed after confirming the source and monitoring request volume.
Identity
- User-Agent Pattern
-
TwinWaveScanner - HTTP Agent Examples
-
TwinWaveScanner - Robots Token
- TwinWaveScanner
- Identity Type
- Observed
- Evidence Method
- Treat `TwinWaveScanner` as an identity signal only. Confirm it with current operator documentation, cryptographic verification, forward-confirmed reverse DNS, source-network ownership, or other authoritative evidence before trusting the claimed identity.
Classification
- Type
- Feed
- Kind
- Fetcher
- Family
- Splunk
- Purpose
- AI training
Behavior and handling
- Common Use
- Splunk Attack Analyzer is used for AI model training, dataset discovery, and collection of public web content for model-development pipelines.
- Detection Notes
- Splunk Attack Analyzer traffic is primarily detected by the `TwinWaveScanner` user-agent pattern. Compare source IPs, reverse DNS, request paths, and crawl cadence with Splunk infrastructure before trusting the traffic.
- Respects robots.txt
- Unknown
- Spoofing Risk
- Splunk Attack Analyzer has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.
- Risk
- Safe
- Recommended Handling
- Do not block
Rules and controls
- Robots.txt Snippet
-
# robots.txt behavior is unconfirmed. Do not rely on this rule without verification.
Relationships
- Operator
- Splunk Checked 2026-08-07
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.