Skip to main content

Scenario Coverage

DSP uses scenario plugins under scenarios/<id>/. The current operational profile contains eleven customer-facing scenarios. dsp plugins list is the authoritative view for the installed build because development branches may contain additional internal/test plugins.

Operational scenario set

These are activity and signal targets, not alert guarantees. Whether an XDR/NDR product creates a detection depends on sensor visibility, policy, rules/models, and the customer environment.

How to choose scenarios for a POC

For most evaluations, start with the normal profile and let DSP select the full active scenario order. Use explicit scenarios only when the POC has a narrow objective, such as DNS tunneling or web-attack visibility.

Network and discovery

  • port_sweep
  • rare_protocol_activity

DNS

  • dga
  • dns_tunnel

Web

  • http_followup
  • sql_injection

Identity/service behavior

  • ssh_failure
  • ldap_enumeration
  • smb_login_failure
  • kerberos_failure

Host behavior

  • host_behavior_check creates controlled host-side activity that can provide additional context when the XDR environment collects host telemetry.

Profile behavior

Both current profiles use the same ordered scenario set:
The difference is target coverage:
  • normal — representative targets, generally up to two for service-oriented scenarios
  • high — same per-target volume, expanded across more discovered targets subject to guardrails
Service-specific scenarios only become meaningful when the corresponding host/service is reachable in the target environment.

Run a specific subset

Replace the example CIDR with the authorized scope.

Check active plugins