rational-sitecheck
Rational SiteCheck is a web crawler operated by IBM Rational, a division of IBM, first introduced as part of the IBM Rational AppScan product suite in 2005. Its primary purpose is to automatically discover and map web application structures, including URLs, forms, parameters, and cookies, to facilitate comprehensive security vulnerability scanning. The crawler feeds data into the AppScan engine, which performs static and dynamic analysis to identify common web vulnerabilities such as SQL injection, cross-site scripting, and authentication flaws. It is a legitimate, commercially licensed tool used by security professionals for penetration testing and compliance audits.
During scanning, Rational SiteCheck employs a depth-first crawl strategy, following all hyperlinks and form submissions within the target domain, including JavaScript-generated links and AJAX calls when configured. It sends requests at a configurable rate, typically between 10 to 50 requests per second, but can be throttled to avoid disruption. The bot uses HTTP/1.1 and supports HTTPS, often sending custom headers like X-Requested-With: XMLHttpRequest to simulate real user behavior. IP ranges are not published but originate from IBM’s corporate address blocks in the United States and Europe. It respects Robots.txt directives by default, but users can override this for thorough testing. The crawler also processes sitemap.xml files for coverage.
According to IBM’s official documentation for AppScan, the crawler honors Disallow directives in robots.txt by default, but provides an option to ignore them for authorized penetration testing. This dual behavior is explicitly documented in the IBM Knowledge Center. For non-testing use, the bot will avoid paths listed as disallowed. Site owners can control access by adding specific User-agent entries for Rational SiteCheck or AppScan.
The primary User-Agent string is Mozilla/5.0 (compatible; Rational SiteCheck/1.0; +http://www.ibm.com/software/rational/appscan/) or variations. Additional fingerprints include a high frequency of HEAD and GET requests, lack of Accept-Language header, and sequential URL parameter testing. The bot also sends unique cookies like AppScanSession during scans. Log entries often show rapid sequential access patterns across directories.
Collected data—including page structures, form inputs, and response codes—is used exclusively for vulnerability analysis and reporting within IBM Rational AppScan. No data is stored longer than the scan session, and results are presented to the user as a security assessment report. This is not used for AI training or public indexing; it is strictly for security audit purposes.
Because Rational SiteCheck can generate high request volumes during comprehensive scans, it is rate-limited by default to prevent accidental denial-of-service on target servers. Threshold-based blocking is recommended when the crawler exceeds a site's capacity, but administrators should whitelist IBM’s IP ranges during authorized security tests to avoid false positives.
Similar Threats
Free Traffic Analysis
Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.