analyzing-web-server-logs-for-intrusion

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly dete

By mukul975 · 396 installs

npx skills add mukul975/anthropic-cybersecurity-skills --skill analyzing-web-server-logs-for-intrusion

Source repository · Upstream listing

Analyzing Web Server Logs for Intrusion When to Use When investigating security incidents that require analyzing web server logs for intrusion When building detection rules or threat hunting queries for this domain When SOC analysts need structured procedures for this analysis type When validating security monitoring coverage for related attack techniques Prerequisites Familiarity with security operations concepts and tools Access to a test or lab environment for safe execution Python 3.8+ with required dependencies installed Appropriate authorization for any testing activities Instructions 1. Install dependencies: pip install geoip2 user agents 2. Collect web server access logs in Combined Log Format (Apache) or Nginx default format. 3. Parse each log entry extracting: IP, timestamp, method, URI, status code, response size, user agent, referer. 4. Apply detection rules: SQL injection: UNION SELECT , OR 1=1 , ' OR ' , hex encoding patterns LFI/Path traversal: ../ , /etc/passwd , /proc/self , php://filter XSS: <script , javascript: , onerror= , onload= Scanner signatures: nikto, sqlmap, dirbuster, gobuster, wfuzz user agents Brute force: 50 POST requests to login endpoints from same IP in 5 minutes 5. Enrich with GeoIP data and generate a prioritized findings report. Examples Detect SQLi in URI Scanner User Agent Detection