Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
mukul975 avatar

Analyzing Web Server Logs For Intrusion

  • 314 installs
  • 27.3k repo stars
  • Updated August 2, 2026
  • mukul975/anthropic-cybersecurity-skills

Detect and investigate suspicious activity in web server logs to identify potential intrusions or security breaches.

About

This skill teaches how to parse, search, and analyze web server logs to detect unauthorized access attempts, malicious payloads, and anomalous behavior. A solo builder uses it when investigating security incidents or implementing proactive threat monitoring on their production systems. It matters because early intrusion detection can prevent data breaches, unauthorized access, and service disruptions.

  • Detect suspicious patterns in HTTP requests and access logs
  • Identify common attack vectors like SQL injection and XSS attempts
  • Correlate log data to investigate security incidents

Analyzing Web Server Logs For Intrusion by the numbers

  • 314 all-time installs (skills.sh)
  • +18 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #622 of 2,203 Security skills by installs in the Skillselion catalog
  • Security screen: HIGH risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill analyzing-web-server-logs-for-intrusion

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs314
repo stars27.3k
Security audit2 / 3 scanners passed
Last updatedAugust 2, 2026
Repositorymukul975/anthropic-cybersecurity-skills

What it does

Detect and investigate suspicious activity in web server logs to identify potential intrusions or security breaches.

Files

SKILL.mdMarkdownGitHub ↗

Analyzing Web Server Logs for Intrusion

When to Use

  • When investigating security incidents that require analyzing web server logs for intrusion
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with security operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

1. Install dependencies: pip install geoip2 user-agents 2. Collect web server access logs in Combined Log Format (Apache) or Nginx default format. 3. Parse each log entry extracting: IP, timestamp, method, URI, status code, response size, user-agent, referer. 4. Apply detection rules:

  • SQL injection: UNION SELECT, OR 1=1, ' OR ', hex encoding patterns
  • LFI/Path traversal: ../, /etc/passwd, /proc/self, php://filter
  • XSS: <script>, javascript:, onerror=, onload=
  • Scanner signatures: nikto, sqlmap, dirbuster, gobuster, wfuzz user-agents
  • Brute force: >50 POST requests to login endpoints from same IP in 5 minutes

5. Enrich with GeoIP data and generate a prioritized findings report.

python scripts/agent.py --log-file /var/log/nginx/access.log --geoip-db GeoLite2-City.mmdb --output web_intrusion_report.json

Examples

Detect SQLi in URI

192.168.1.100 - - [15/Jan/2024:10:30:45 +0000] "GET /products?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 4532

Scanner User-Agent Detection

Nikto/2.1.6, sqlmap/1.7, DirBuster-1.0-RC1, gobuster/3.1.0

Related skills

FAQ

Is Analyzing Web Server Logs For Intrusion safe to install?

skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.