
A 404 is still a response. The scanner reads it, your app may render a page for it, and your log gets a line. nginx's return 444 closes the connection without sending anything. The request never reaches the application, and the scanner learns nothing from it.
Map the bad user agents
Put the user-agent map in the http context. The default 0 line keeps everything else allowed, and the empty user agent is flagged because real browsers always send one.
Match the probe paths in the server block
Dotfiles outside /.well-known/ and the usual admin paths get closed. The if block only returns, which is the one form of if nginx documents as safe.
Test the config and reload
Check that the probes are closed
curl reports 000 when the connection closes without a response, which is what you want for a probe. The Python check below runs the same probes and reports what each one got back.
Don't block the crawlers you want
Search engines and uptime checks send their own user agents. Before you add a pattern to the map, check the log for the exact string, and keep the list short. A deny list that catches a real crawler costs more than the probes it stops.
For the scrapers that ignore robots.txt, osec Bot Gate adds one more layer without moving your DNS.

Sources
• nginx rewrite module (return, including 444): https://nginx.org/en/docs/http/ngx_http_rewrite_module.html
• nginx map module: https://nginx.org/en/docs/http/ngx_http_map_module.html