deltascan

Scanner User-Agent: deltascan

🤖 Overview

Deltascan is a web crawler operated by Delta DNA Inc., a cybersecurity company headquartered in San Francisco that provides automated vulnerability scanning services. Its purpose is to crawl publicly accessible web applications to detect security flaws such as cross-site scripting (XSS), SQL injection, and insecure configuration errors. The collected data feeds into Delta DNA’s proprietary vulnerability reporting platform, which delivers actionable risk assessments to subscribing website owners.

🌐 Technical Behavior

Deltascan employs a distributed architecture using a rotating pool of IP addresses sourced primarily from Amazon Web Services and Google Cloud Platform. It issues HTTP GET and POST requests at a rate of 1–3 requests per second per IP during standard scans, but can escalate to 10 requests per second for deep “full-coverage” audits. The crawler respects HTTP caching headers (e.g., Cache-Control and ETag) to avoid redundant fetches, and it handles both gzip and brotli compression. It parses HTML, JavaScript, CSS, and robots.txt files, and follows all anchor links and redirects recursively. According to a Delta DNA blog post from March 2024, the crawler also analyzes JavaScript-based dynamic content using a headless Chrome instance to uncover client-side vulnerabilities.

📋 robots.txt Compliance

Delta DNA’s official documentation (published at deltadna.com/bot) confirms that Deltascan honors all Disallow directives found in robots.txt files. The company advises website owners to include User-agent: Deltascan and Disallow: / if they wish to completely exclude the scanner. They also provide a web-based “Scan Exclusion Manager” tool to whitelist specific paths without editing robots.txt.

🔍 Detection Indicators

The primary User-Agent strings are Deltascan/1.0 and Deltascan/2.0, often followed by the URL (https://deltadna.com/bot). Additional identifying signals include a custom HTTP header X-DeltaScan-Version: 2.0 and a From header containing [email protected]. The IP ranges are publicly listed in their ASN (AS16509, AS14618) and include blocks such as 3.12.0.0/16 and 18.224.0.0/14.

📊 Data Usage

The scan results—including detected vulnerabilities, response times, and page structure—are compiled into per-customer security reports. Delta DNA states it does not sell or share raw scan data; only anonymized aggregate statistics (e.g., vulnerability prevalence) are used for internal research and industry publications, such as their annual Web Security Trends Report.

⚙️ Rate Limiting Policy

Although Deltascan is a legitimate security assessment tool, its scalable scanning engine can impose significant load on origin servers, especially during deep audits of large sites. Administrators are recommended to apply rate-limiting at 5 requests per second per IP to preserve server stability while still allowing the beneficial vulnerability scan to complete.

🛡️

Stop Bots. Save Bandwidth. Protect Revenue.

Boteraser automatically detects and blocks unwanted bots — protecting your site from scrapers, DDoS bursts, and credential stuffing attacks without slowing down real visitors.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.