Scenario Coverage
DSP uses scenario plugins underscenarios/<id>/. The current operational profile contains eleven customer-facing scenarios. dsp plugins list is the authoritative view for the installed build because development branches may contain additional internal/test plugins.
Operational scenario set
These are activity and signal targets, not alert guarantees. Whether an XDR/NDR product creates a detection depends on sensor visibility, policy, rules/models, and the customer environment.
How to choose scenarios for a POC
For most evaluations, start with thenormal profile and let DSP select the full active scenario order. Use explicit scenarios only when the POC has a narrow objective, such as DNS tunneling or web-attack visibility.
Network and discovery
port_sweeprare_protocol_activity
DNS
dgadns_tunnel
Web
http_followupsql_injection
Identity/service behavior
ssh_failureldap_enumerationsmb_login_failurekerberos_failure
Host behavior
host_behavior_checkcreates controlled host-side activity that can provide additional context when the XDR environment collects host telemetry.
Profile behavior
Both current profiles use the same ordered scenario set:normal— representative targets, generally up to two for service-oriented scenarioshigh— same per-target volume, expanded across more discovered targets subject to guardrails