Analyzing Web Server Logs For Intrusion

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.

theheavenlyd3mon 7ad71dc 4 files · 22.9 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/analyzing-web-server-logs-for-intrusion commit 7ad71dcb91

Frequently asked questions

npx skillmds add theheavenlyd3mon/analyzing-web-server-logs-for-intrusion