← Digital forensicstriage web attacks in your access.log in 5 minutes

triage web attacks in your access.log in 5 minutes

$grep -E '\.\./|union select|<script>' access.log

your access.log has been quietly recording everything, go read it

every request that hits your web server gets logged whether you look at it or not. most people never open this file until something's already on fire. but access.log is basically a security camera that's been running the whole time, you just have to know what to look for. here's a 5 minute triage you can run right now on your own server.

step 1: find the ip's doing way too much

start broad. you're looking for one address hammering your server way more than normal traffic would explain.

awk '{print $1}' access.log | sort | uniq -c | sort -rn | head -20

this pulls the first field (the client ip) out of every log line, counts how many times each one shows up, and sorts it so the busiest ip's are at the top. a real visitor might hit your site a few dozen times. an ip with 4,000 requests in an hour is either a bot, a scraper, or someone probing you. not automatically malicious, but it's your starting suspect list.

step 2: count the 404s, that's your scanner fingerprint

attackers (and plenty of automated bots) don't know your site structure, so they guess. they'll request /admin, /wp-login.php, /.env, /config.old, hundreds of paths that don't exist on your server, hoping one sticks.

awk '$9 == 404 {print $1}' access.log | sort | uniq -c | sort -rn | head -20

$9 is the http status code field in the common log format, you might need to adjust the field number depending on your log format. an ip racking up dozens or hundreds of 404s in a short window is doing path enumeration. it's the digital version of someone walking down a hallway trying every door handle.

step 3: grep for the actual attack strings

this is the command from the reel, and it's the fast way to catch the attempts that aren't just guessing, they're actively trying to break something.

grep -E '\.\./|union select|