Analyzing Web Server Logs For Intrusion

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/analyzing-web-server-logs-for-intrusion commit 7627989e5d

Frequently asked questions

npx skillmds@latest add 26zl/analyzing-web-server-logs-for-intrusion