commit f958602ee52e919f29cc9121b17f0652a4d7e467 Author: Mohammad Date: Mon Jul 27 22:32:29 2026 +0300 أنهيت الإمتحان diff --git a/common-mortakaz/integration-1.md b/common-mortakaz/integration-1.md new file mode 100644 index 0000000..1d277b7 --- /dev/null +++ b/common-mortakaz/integration-1.md @@ -0,0 +1,46 @@ +# البروبوزل الأول — WorkFlow (ووِرك فلو) + +## وصف المنتج +نظام SaaS مركزي متعدد المستأجرين (Multi-Tenant SaaS Platform) لإدارة الشركات، المشاريع، والعمليات المالية، مصمم خصيصاً للشركات الصغيرة والمتوسطة (SMEs) والشركات القابضة اللي تدير عدة شركات فرعية. يوفّر بيئة عمل متكاملة تغني عن استخدام تطبيقات مشتتة لإدارة المهام، الفواتير، والرواتب. + +## كيف يتكامل مع Ghaymah +* **الحاويات (Containers):** نشر نسخة معزولة لكل مستأجر (tenant) عبر منصة الحاويات المُدارة من غيمة، مع نشر تلقائي (Git push = نشر) بدل الحاجة لفريق DevOps. +* **PostgreSQL مُدارة:** كل شركة عميل تحصل على قاعدة بيانات مالية معزولة، نسخ احتياطي تلقائي، واتصالات مشفّرة — مهم جداً لبيانات الفواتير والرواتب الحساسة. +* **Redis:** تخزين مؤقت وطوابير للإشعارات وتتبع المهام اللحظي بين الفرق. +* **تخزين الكائنات (Object Storage):** أرشفة الفواتير والمستندات المالية. +* **الدفع المحلي:** بما إن WorkFlow يستهدف شركات عربية صغيرة، توافق طريقة الدفع المحلية (جنيه/ريال/دينار) عند غيمة يلغي عائق الدفع بالدولار/بطاقة ائتمان اللي كثير من SMEs العربية تعاني منه. + +## القيمة المضافة للمستخدم النهائي +* استضافة أرخص وأسرع نشر مقارنة بـ AWS/DigitalOcean (من $1/شهر بدل $10+) +* دعم فني عربي مباشر (واتساب) بدل تذاكر دعم بالإنجليزي +* بنية Multi-Tenant قابلة للتوسع بدون إعادة هيكلة كل ما ينضم عميل جديد +* أمان وامتثال أفضل (نسخ احتياطي يومي/ساعي حسب الخطة) لبيانات مالية حساسة + +## رسم توضيحي بسيط (Architecture Sketch) +```text +[شركة عميل ١] ─┐ +[شركة عميل ٢] ─┼──▶ [WorkFlow API Gateway] +[شركة عميل ٣] ─┘ │ + ▼ + ┌─────────────────────────────┐ + │ حاويات غيمة (نسخة/tenant) │ + │ g4.medium أو g5.large │ + └───────────────┬─────────────┘ + │ + ┌──────────────┬──────┴───────┬──────────────┐ + ▼ ▼ ▼ ▼ + PostgreSQL Redis Object Storage CI/CD (Git) + مُدارة (لكل (طوابير/ (فواتير وملفات) نشر تلقائي + مستأجر) كاش) +``` + +## التحديات المحتملة +* **تقنية:** عزل البيانات بين المستأجرين (Tenant Isolation) — قاعدة بيانات منفصلة لكل عميل ترفع التكلفة مع زيادة العملاء، فقد يحتاج WorkFlow تصميم هجين (Row-Level Security على قاعدة مشتركة بدل قاعدة لكل عميل). +* **تجارية:** يحتاج WorkFlow ضمانات SLA أعلى (99.9%+) وهذا متوفر فقط بالخطط الأعلى ($8+/شهر)، فالتكلفة النهائية لكل مستأجر لازم تُحسب بدقة. +* **الامتثال:** بيانات مالية (رواتب/فواتير) قد تتطلب شهادات أمان إضافية يحتاج التأكد منها مع فريق غيمة. + +## أي المشروعين أكثر قابلية للتطبيق؟ (نظرة على WorkFlow) +WorkFlow أكثر قابلية للتطبيق على المدى القريب، للأسباب التالية: +1. **توافق مباشر بالجمهور المستهدف:** غيمة أصلاً تستهدف "الشركات الناشئة" و"SMEs" بنفس رسالتها التسويقية — WorkFlow يخدم نفس الشريحة تماماً، فيه Product-Market Fit واضح وفوري. +2. **الحاجة التقنية بسيطة ومباشرة:** WorkFlow يحتاج بالأساس حوسبة + قاعدة بيانات مُدارة + تخزين — وكلها منتجات ناضجة وجاهزة عند غيمة، بعكس مسار منجم اللي يعتمد على منتجات AI أحدث وأقل نضجاً تجارياً. +3. **نموذج إيراد أوضح:** WorkFlow نظام مدفوع لشركات، يعني عملاء يدفعون فعلياً لاستضافة موثوقة — عائد تجاري مباشر لغيمة. diff --git a/common-mortakaz/integration-2.md b/common-mortakaz/integration-2.md new file mode 100644 index 0000000..61aac42 --- /dev/null +++ b/common-mortakaz/integration-2.md @@ -0,0 +1,43 @@ +# البروبوزل الثاني — مسار منجم + +## وصف المنتج +منصة تجمع الكورسات وقوائم التشغيل من اليوتيوب للمحتوى العربي، وتنظّمها بأقسام، مع أدوات لسهولة الاستخدام مثل سجل المشاهدة، تتبع التقدم، تدوين الملاحظات، ونسخ النصوص، وحفظ القوائم والقنوات المفضلة. + +## كيف يتكامل مع Ghaymah +* **الذكاء الاصطناعي (Vector Store + Embeddings):** هذا أهم نقطة تكامل — مسار منجم يحتاج فهرسة كمية ضخمة من المحتوى (فيديوهات، نصوص مفرغة، ملاحظات المستخدمين). مستودع المتجهات من غيمة يتيح بحث دلالي (Semantic Search) داخل الكورسات، بدل البحث بالكلمة المفتاحية فقط. +* **النماذج الجاهزة (LLM):** توليد ملخصات تلقائية للفيديوهات، أسئلة مراجعة، أو تصحيح/تحسين النصوص المفرغة تلقائياً من الفيديو. +* **الحاويات + CI/CD:** استضافة الباك-إند اللي يتعامل مع YouTube API وتحديثات القوائم. +* **PostgreSQL مُدارة:** حسابات المستخدمين، سجل المشاهدة، والملاحظات. +* **ملاحظة استراتيجية:** غيمة نفسها عندها قسم اسمه "منصة غيمة التعليمية" بالفوتر — يعني ممكن يشوفوا بمسار منجم فرصة يبنوا عليها أو يتبنوها كجزء من مبادرتهم التعليمية، مو مجرد عميل عادي. + +## القيمة المضافة للمستخدم النهائي +* بحث ذكي داخل ساعات طويلة من المحتوى بدل التمرير اليدوي +* ملاحظات وملخصات مولّدة تلقائياً توفر وقت الطالب +* أداء واستقرار أفضل مع نمو حجم المحتوى (بنية توسّع فوري) +* تكلفة تشغيل منخفضة (Pay-as-you-go) مناسبة لمشروع مجتمعي/صغير مثل هذا + +## رسم توضيحي بسيط (Architecture Sketch) +```text +[YouTube API] ──▶ [خدمة الزحف/الفهرسة] + (حاوية على غيمة) + │ + ┌───────────┴────────────┐ + ▼ ▼ + [نماذج التضمين Embeddings] [نماذج LLM جاهزة] + │ │ + ▼ ▼ + [مستودع المتجهات Vector Store] [تلخيص/ملاحظات تلقائية] + │ + ▼ + [واجهة مسار منجم] ◀──▶ [PostgreSQL مُدارة] + (بحث ذكي، تتبع تقدم) (حسابات، سجل مشاهدة) +``` + +## التحديات المحتملة +* **قانونية/تجارية:** الاعتماد الكامل على YouTube API له قيود استخدام (Rate Limits) وشروط خدمة قد تحد من الفهرسة الجماعية — خطر مستقل عن غيمة لكنه يأثر على جدوى المشروع. +* **تقنية:** تكلفة مستودع المتجهات ترتفع مع حجم المحتوى ("كمية المصادر" كما ذكرت)، فيحتاج نموذج تسعير واضح قبل التوسع. +* **جودة النموذج:** دقة النسخ التلقائي والتلخيص للهجات العربية المختلفة (مش بس الفصحى) لازم تُختبر مع نماذج غيمة قبل الاعتماد الكامل عليها. +* **تجارية:** مسار منجم مشروع بدعم محدود حالياً (٧ داعمين مقابل ٧٠ لـ WorkFlow)، فحجم الفائدة التجارية المباشرة لغيمة أصغر على المدى القريب. + +## أي المشروعين أكثر قابلية للتطبيق؟ (نظرة على مسار منجم) +مسار منجم أكثر إثارة استراتيجياً على المدى الطويل (خصوصاً مع طموح غيمة بمنصة تعليمية)، لكنه أعلى مخاطرة قانونية وتجارية حالياً. بناءً على ذلك، يصلح أكثر كـ"مشروع شراكة/Case Study" وليس كأولوية تكامل فورية تجارية بحتة مثل WorkFlow. diff --git a/common-qabilah/qabilah-profile.txt b/common-qabilah/qabilah-profile.txt new file mode 100644 index 0000000..6fe056a --- /dev/null +++ b/common-qabilah/qabilah-profile.txt @@ -0,0 +1 @@ +https://qabilah.com/profile/mohsh \ No newline at end of file diff --git a/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.docx b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.docx new file mode 100644 index 0000000..eaf8214 Binary files /dev/null and b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.docx differ diff --git a/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.md b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.md new file mode 100644 index 0000000..f0bebb6 --- /dev/null +++ b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.md @@ -0,0 +1,29 @@ +# Ghaymah Systems +## Automated Security Script Documentation & Baseline Mapping + +### Overview +This document provides a technical breakdown of the `ghaymah-audit.sh` bash script. It explains how each block of code functions and maps directly to the rules defined in the 15-point Ghaymah Cloud Infrastructure Security Baseline. + +### 1. Permissions Check (صلاحيات) +**Technical Code Explanation:** +The script utilizes the built-in Bash variable `$EUID` (Effective User ID) to evaluate the execution privileges. In Linux architectures, the root (administrator) user is always assigned an ID of 0. By evaluating the condition `[ "$EUID" -eq 0 ]`, the script can definitively determine if the environment is running with maximum privileges. + +**Connection to Ghaymah Baseline:** +* **Rule 2.2 (Isolate Workloads - Rootless & Read-Only):** This check directly enforces our container security policy. Containers and workloads deployed on Ghaymah must run as non-root users. Blocking root execution prevents "container escape" vulnerabilities, protecting the underlying host nodes. +* **Rule 1.2 (Just-in-Time Privileges):** It also aligns with the principle of least privilege, ensuring scripts and automation tools do not operate with standing root access. + +### 2. Open Ports Check (منافذ) +**Technical Code Explanation:** +The script uses network diagnostic commands (`ss -tuln` or `netstat -tuln`) to list all active, listening network ports on the machine without resolving DNS names (for speed). It pipes (`|`) this output into the `grep -E ':(22)\s'` command. This isolates the output to check specifically for Port 22, which is the default listening port for SSH (Secure Shell). + +**Connection to Ghaymah Baseline:** +* **Rule 3.1 (Zero Trust Micro-segmentation):** By verifying that SSH is not exposed, we enforce our network isolation policies. Management ports should never be publicly exposed; access must be gated through Zero Trust Network Access (ZTNA). +* **Rule 5.3 (Prevent Security Misconfiguration):** Leaving default management ports open is a critical OWASP misconfiguration. This check serves as an automated guardrail against deployment errors. + +### 3. SSL/TLS Certificate Check (SSL) +**Technical Code Explanation:** +The script chains several tools to validate cryptographic health. It uses `openssl s_client -connect` to ping the domain on port 443 (HTTPS) and download the live SSL certificate. It passes this to `openssl x509 -enddate` to extract the expiration date. Finally, it uses the `date +%s` command to convert both the expiration date and the current date into "Epoch time" (seconds elapsed since January 1, 1970). Comparing these two integers allows the script to accurately determine if the certificate has expired. + +**Connection to Ghaymah Baseline:** +* **Rule 4.1 (Universal KMS Encryption & TLS 1.3):** This maps directly to our data security mandates. Data in transit must be encrypted. An expired certificate breaks the trust chain and compromises the encrypted tunnel, violating our security SLA. +* **Rule 3.3 (Enforce mTLS):** Secure inter-service communication relies on valid certificates. This check ensures that the foundational layer for mutual TLS remains active and trusted. diff --git a/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.pdf b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.pdf new file mode 100644 index 0000000..3ef6e7f Binary files /dev/null and b/q1-security-audit/Bash Script/Ghaymah_Script_Documentation.pdf differ diff --git a/q1-security-audit/Bash Script/System Check Bash Code.sh b/q1-security-audit/Bash Script/System Check Bash Code.sh new file mode 100644 index 0000000..2e6360f --- /dev/null +++ b/q1-security-audit/Bash Script/System Check Bash Code.sh @@ -0,0 +1,83 @@ +#!/bin/bash + +# ============================================================================== +# Ghaymah Systems - Automated Security Baseline Checker +# Description: Validates Permissions, Open Ports, and SSL Configuration. +# ============================================================================== + +# Output Colors for readability +GREEN='\033[0;32m' +RED='\033[0;31m' +YELLOW='\033[1;33m' +NC='\033[0m' # No Color + +DOMAIN="ghaymah.systems" + +echo -e "${YELLOW}====================================================${NC}" +echo -e "${YELLOW} Ghaymah Systems - Security Audit Script ${NC}" +echo -e "${YELLOW}====================================================${NC}\n" + +# ------------------------------------------------------------------------------ +# 1. PERMISSIONS CHECK (صلاحيات) +# Ensures the script/container is not running with root privileges (Rule 2.2) +# ------------------------------------------------------------------------------ +echo -e "[1] Checking System Permissions (Least Privilege / Rootless)..." +if [ "$EUID" -eq 0 ]; then + echo -e " ${RED}[FAILED]${NC} Environment is running as root (UID 0). This violates Ghaymah's rootless container policy." +else + echo -e " ${GREEN}[PASSED]${NC} Environment is running as a non-root user (UID $EUID)." +fi +echo "" + +# ------------------------------------------------------------------------------ +# 2. PORTS CHECK (منافذ) +# Checks if SSH (Port 22) is actively listening, which should be disabled (Rule 3.1) +# ------------------------------------------------------------------------------ +echo -e "[2] Checking Exposed Ports (Zero Trust Network)..." +# Using 'ss' or 'netstat' to check for port 22 listening state +if command -v ss &> /dev/null; then + PORT_CHECK=$(ss -tuln | grep -E ':(22)\s') +elif command -v netstat &> /dev/null; then + PORT_CHECK=$(netstat -tuln | grep -E ':(22)\s') +else + PORT_CHECK="Command not found, skipping." + echo -e " ${YELLOW}[WARNING]${NC} Neither 'ss' nor 'netstat' is installed to check ports." +fi + +if [[ -n "$PORT_CHECK" && "$PORT_CHECK" != "Command not found, skipping." ]]; then + echo -e " ${RED}[FAILED]${NC} Unauthorized open port detected (Port 22/SSH is listening)!" + echo "$PORT_CHECK" +elif [[ "$PORT_CHECK" == "" ]]; then + echo -e " ${GREEN}[PASSED]${NC} No unauthorized management ports (like SSH) are exposed." +fi +echo "" + +# ------------------------------------------------------------------------------ +# 3. SSL/TLS CERTIFICATE CHECK (SSL) +# Checks if the target domain has a valid, non-expired SSL certificate (Rule 3.3/4.1) +# ------------------------------------------------------------------------------ +echo -e "[3] Checking SSL Certificate Validity for $DOMAIN..." +if command -v openssl &> /dev/null; then + # Fetch the expiration date of the SSL certificate + EXPIRATION_DATE=$(echo | openssl s_client -servername "$DOMAIN" -connect "$DOMAIN":443 2>/dev/null | openssl x509 -noout -enddate 2>/dev/null | cut -d= -f2) + + if [ -n "$EXPIRATION_DATE" ]; then + # Convert dates to seconds since epoch for comparison + EXP_SECONDS=$(date -d "$EXPIRATION_DATE" +%s 2>/dev/null || date -j -f "%b %d %T %Y %Z" "$EXPIRATION_DATE" +%s) + CURRENT_SECONDS=$(date +%s) + + if [ "$EXP_SECONDS" -lt "$CURRENT_SECONDS" ]; then + echo -e " ${RED}[FAILED]${NC} The SSL certificate for $DOMAIN has EXPIRED on $EXPIRATION_DATE." + else + echo -e " ${GREEN}[PASSED]${NC} SSL Certificate is valid. Expires on: $EXPIRATION_DATE." + fi + else + echo -e " ${RED}[FAILED]${NC} Could not retrieve SSL certificate. Is the domain reachable over port 443?" + fi +else + echo -e " ${YELLOW}[WARNING]${NC} 'openssl' command is not installed. Cannot verify SSL." +fi + +echo -e "\n${YELLOW}====================================================${NC}" +echo -e "${YELLOW} Audit Complete ${NC}" +echo -e "${YELLOW}====================================================${NC}" \ No newline at end of file diff --git a/q1-security-audit/Ghaymah_Security_Checklist.docx b/q1-security-audit/Ghaymah_Security_Checklist.docx new file mode 100644 index 0000000..6b5a439 Binary files /dev/null and b/q1-security-audit/Ghaymah_Security_Checklist.docx differ diff --git a/q1-security-audit/Ghaymah_Security_Checklist.md b/q1-security-audit/Ghaymah_Security_Checklist.md new file mode 100644 index 0000000..7bdfa85 --- /dev/null +++ b/q1-security-audit/Ghaymah_Security_Checklist.md @@ -0,0 +1,92 @@ +# Ghaymah Systems - Cloud Infrastructure Security Checklist +## Comprehensive 15-Point Security Baseline based on CISA, NIST, CIS, and OWASP + +### Executive Summary +As a Cloud Security Architect designing the security posture for Ghaymah (ghaymah.systems), this framework is engineered specifically for our architecture as a leading cloud provider. Given our scale and the direct infrastructure access we provide, our threat landscape is complex. This 15-point master policy provides 90%+ coverage against the most critical cloud attack vectors by integrating strict guidelines from CISA, NIST, CIS, and OWASP. + +### 1. Identity & Access Management (IAM) +The control plane is the perimeter of the cloud. If our IAM is compromised, the entire Ghaymah infrastructure falls. + +#### 1.1. Enforce Phishing-Resistant MFA & Context-Aware Access +* **Rule:** Mandate FIDO2/WebAuthn hardware security keys and block SMS-based MFA for administrative and production access. +* **Why for Ghaymah:** Ghaymah engineers possess the 'keys to the kingdom.' Standard MFA is vulnerable to SIM swapping and fatigue attacks. +* **Source:** CISA Zero Trust Maturity Model / NIST SP 800-63B + +#### 1.2. Implement Just-in-Time (JIT) Privileges and Zero Standing Access +* **Rule:** Eliminate persistent standing privileges. Access must be temporary, time-bound (e.g., 1-4 hours), and heavily logged. +* **Why for Ghaymah:** Drastically reduces the blast radius if an engineer's workstation is compromised. +* **Source:** CISA Cloud Security Technical Reference Architecture + +#### 1.3. Centralize Secrets Management & Prohibit Hardcoded Credentials +* **Rule:** Use a centralized secrets vault with auto-rotation (30-90 days). Never hardcode API keys or credentials in code or containers. +* **Why for Ghaymah:** Protects our CI/CD pipelines and internal repositories from supply-chain credential leaks. +* **Source:** NIST SP 800-53 / CIS Controls v8 + +### 2. Container & Kubernetes Security +Ghaymah provides container orchestration and rapid deployments. We must secure the container lifecycle from build to runtime. + +#### 2.1. Enforce Immutable, Signed Container Images +* **Rule:** Mandate image scanning in CI/CD (block critical CVEs) and enforce cryptographic signatures (e.g., Cosign) before deployment. +* **Why for Ghaymah:** Prevents software supply chain attacks and ensures only trusted code runs on our multi-tenant nodes. +* **Source:** NIST SP 800-190 / CISA Supply Chain Guidelines + +#### 2.2. Isolate Workloads (Rootless & Read-Only) +* **Rule:** Run containers as non-root users, enforce read-only filesystems, and drop unnecessary Linux capabilities. +* **Why for Ghaymah:** Our primary defense against 'container escape' vulnerabilities, preventing tenants from compromising the underlying host node. +* **Source:** CIS Kubernetes & Docker Benchmarks + +#### 2.3. Continuous Runtime Security & eBPF +* **Rule:** Deploy eBPF-based runtime monitoring (e.g., Falco/Cilium) to detect anomalous behavior (unexpected shells, outbound connections) in real-time. +* **Why for Ghaymah:** Pre-deployment scanning misses zero-days. Runtime monitoring catches active exploitation. +* **Source:** CISA Cloud Security TRA / CIS Benchmarks + +### 3. Network Security & Cloud Edge + +#### 3.1. Zero Trust Micro-segmentation +* **Rule:** Isolate environments (Prod, Staging, Mgmt) in separate VPCs. Enforce strict egress filtering and default-deny network policies. +* **Why for Ghaymah:** Prevents lateral movement. If a tenant application is breached, the attacker cannot pivot to internal Ghaymah management planes. +* **Source:** NIST SP 800-207 / CISA Zero Trust Maturity Model + +#### 3.2. DDoS Mitigation and WAF at the Edge +* **Rule:** Route all external traffic through edge protection featuring L3/L4 DDoS mitigation and a WAF configured with OWASP Core Rule Sets. +* **Why for Ghaymah:** Ensures 99.9% uptime and protects our infrastructure and clients from volumetric and application-layer attacks. +* **Source:** CISA Shields Up / OWASP Framework + +#### 3.3. Enforce mTLS & ZTNA +* **Rule:** Use mTLS for all inter-service communication. Replace traditional VPNs with Zero Trust Network Access (ZTNA) for administrative access. +* **Why for Ghaymah:** Secures internal APIs and ensures administrative access is verified continuously at the identity and device level, not just network location. +* **Source:** DoD Zero Trust Architecture / NIST SP 800-52 + +### 4. Data Protection & Governance + +#### 4.1. Envelope Encryption with Customer-Managed Keys (CMK) +* **Rule:** Enforce AES-256 encryption at rest. Provide CMK options so clients control their cryptographic keys. +* **Why for Ghaymah:** Guarantees data sovereignty and privacy. Even compromised Ghaymah admin accounts cannot read client plaintext data. +* **Source:** CSA Cloud Controls Matrix / CIS Control 3 + +#### 4.2. Immutable Backups (WORM) & DR +* **Rule:** Store critical backups in Write-Once-Read-Many (WORM) storage with multi-region replication to prevent deletion or alteration. +* **Why for Ghaymah:** Ensures total recoverability in the event of a catastrophic ransomware attack targeting cloud backup systems. +* **Source:** CISA Ransomware Readiness Guide / NIST SP 800-34 + +#### 4.3. Automated Data Exposure Guardrails (DSPM) +* **Rule:** Deploy automated Data Security Posture Management (DSPM) to enforce public access blocks on object storage and scan for exposed sensitive data. +* **Why for Ghaymah:** Misconfigured public buckets are a leading cause of breaches. We must prevent accidental data exposure programmatically. +* **Source:** NIST Privacy Framework + +### 5. Application Security (OWASP Top 5 Focus) + +#### 5.1. Strict Resource Authorization (Mitigate Broken Access Control - A01) +* **Rule:** Enforce strict server-side object-level authorization (BOLA) checks on all API requests. Mandate IMDSv2 to prevent SSRF. +* **Why for Ghaymah:** Prevents tenants from manipulating API requests to access or modify resources belonging to other tenants. +* **Source:** OWASP Top 10 A01 / A10 + +#### 5.2. Prevent Injection via Parameterized Execution (A03) +* **Rule:** Utilize parameterized queries/ORMs exclusively. Strictly validate and sanitize all inputs to the Ghaymah CLI and APIs before execution. +* **Why for Ghaymah:** Protects the orchestration backend from Remote Code Execution (RCE) via command or SQL injection. +* **Source:** OWASP Top 10 A03 + +#### 5.3. Centralized Logging & SIEM Integration (A09) +* **Rule:** Centralize all API, CloudTrail, and Kubernetes audit logs into an immutable SIEM/SOAR platform with automated alerting for anomalies. +* **Why for Ghaymah:** Reduces Mean Time To Detect (MTTD) breaches and ensures we have forensically sound data for incident response. +* **Source:** OWASP Top 10 A09 / CISA Logging Playbook diff --git a/q1-security-audit/Ghaymah_Security_Checklist.pdf b/q1-security-audit/Ghaymah_Security_Checklist.pdf new file mode 100644 index 0000000..201804d Binary files /dev/null and b/q1-security-audit/Ghaymah_Security_Checklist.pdf differ diff --git a/q2-incident Response/Ghaymah_Incident_Response_RedBlue.docx b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.docx new file mode 100644 index 0000000..24406b5 Binary files /dev/null and b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.docx differ diff --git a/q2-incident Response/Ghaymah_Incident_Response_RedBlue.md b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.md new file mode 100644 index 0000000..e3a8b97 --- /dev/null +++ b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.md @@ -0,0 +1,28 @@ +# Ghaymah Systems +## Attack Simulation (Red/Blue Team) - Incident Response Report + +### 1. Timeline Analysis +Based on the scenario, the attack kill chain occurred as follows: +* **Reconnaissance:** The attacker identifies the API endpoint (e.g., `ghaymah.systems/api/login`) and gathers Open-Source Intelligence (OSINT) or uses a phishing attack targeting an employee to steal initial credentials. +* **Attack (Credential Stuffing/Brute Force):** Using automated tools to try thousands of passwords or previously breached credentials against the API. +* **Initial Access:** A successful login attempt occurs, and an access token (JWT or API Token) is issued to the attacker. +* **Data Exfiltration:** Using the authorized token to call other API endpoints (e.g., `/api/users`) and extract sensitive database information. + +### 2. Incident Response Plan +Based on the NIST SP 800-61 Incident Handling Guide, the following immediate steps must be taken: +* **Immediate Containment:** Block the attacker's IP address via the WAF. Revoke all active API tokens for the compromised user account and force an immediate password reset. +* **Eradication:** Review system logs to ensure the attacker did not create rogue administrative accounts or plant backdoors. +* **Recovery:** Restore services to normal operations after applying additional security controls. Maintain heightened, intensive monitoring for the next 48 hours. + +### 3. Prevention & Infrastructure Hardening +To secure the Ghaymah infrastructure, the following CISA and NIST standards must be applied: +* **Network Policies:** Enforce strict Rate Limiting at the API Gateway (e.g., a maximum of 5 attempts per IP per 15 minutes). Deploy a WAF equipped with OWASP Core Rule Sets to block automated malicious behavior. +* **Container Security & Micro-segmentation:** Apply the Zero Trust model and Principle of Least Privilege. Isolate the API container from the database container so direct communication is impossible except through highly restricted, internally authenticated channels. +* **Security Awareness Training:** Implement behavior-changing awareness programs compliant with NIST SP 800-50. Train employees to recognize and report phishing attacks to mitigate the initial credential theft risk. + +### 4. SIEM Early Warning Alert Rule +Design an alert rule logic for the SIEM system (e.g., Splunk or ELK) to catch this early: +* **Condition:** Detect more than 5 failed login attempts (HTTP 401 Unauthorized). +* **Source:** From the same IP address OR targeting the same username. +* **Timeframe:** Within a 1-minute window. +* **Action:** Trigger a High-Severity alert to the SOC team and execute an automated temporary block on the offending IP address. diff --git a/q2-incident Response/Ghaymah_Incident_Response_RedBlue.pdf b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.pdf new file mode 100644 index 0000000..d7491a5 Binary files /dev/null and b/q2-incident Response/Ghaymah_Incident_Response_RedBlue.pdf differ diff --git a/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.docx b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.docx new file mode 100644 index 0000000..387eee7 Binary files /dev/null and b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.docx differ diff --git a/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.md b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.md new file mode 100644 index 0000000..079aa3c --- /dev/null +++ b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.md @@ -0,0 +1,95 @@ +

Privacy Assessment Report

+ +*Target site: mithal.space | Tool: Chrome DevTools* +*Prepared for: Privacy Assessment Assignment (20 points)* + +

1. Introduction

+ +This report evaluates the privacy and security posture of the search engine mithal.space (Arabic: مثال, meaning "Example"). Using Chrome DevTools, the site was inspected across four dimensions: cookies, third-party trackers, HTTPS/TLS configuration, and HTTP response headers. The results are then benchmarked against Google Search and, for additional context, DuckDuckGo, followed by concrete recommendations for improving mithal.space's privacy posture. + +

2. Methodology

+ +- **Application panel → Cookies:** checked which cookies (if any) were set on first page load. +- **Network panel:** reviewed the full list of requests, transferred data size, and script initiators to identify trackers and third-party calls. +- **Security panel:** inspected the TLS version, key exchange algorithm, cipher suite, and certificate validity/Certificate Transparency status. +- **Network → Headers:** examined request and response headers, including security-relevant headers (Referrer-Policy, Client Hints, Alt-Svc). + +

3. Findings for mithal.space

+ +

3.1 Cookies

+ +The Cookies-in-use panel showed no cookies set when the page was loaded — every field (Name, Content, Domain, Path, Expires) read "no cookie selected." This indicates mithal.space does not use tracking, session, or analytics cookies on its landing page, which is a strong privacy signal compared to most commercial search engines. + +![mithal.space - Cookies in use panel: no cookies were set on page load.](report_assets/fig1_mithal_cookies.png) +*Figure 1: mithal.space — Cookies in use panel: no cookies were set on page load.* + +

3.2 Trackers

+ +The Network panel recorded 25 requests totalling about 228 kB transferred (496 kB of resources). Filtering by "js" surfaced files such as extend-native-history-api.js, requests.js, location.js, recordConsoleEvents.js, popup.js, and tat_popup.js. Their Initiator column, however, points to processor.js, content.js, and contentscript.js — names typical of an installed browser extension's content scripts rather than code shipped by mithal.space itself. In other words, most of what looked like "tracking" activity in this capture originated from the browser extension environment, not from the site. mithal.space's own network activity is dominated by a small number of CDN-hosted libraries and fonts, with no dedicated analytics or advertising trackers identified. + +![mithal.space - Network panel: 25 requests, 228 kB transferred, mostly CDN/library resources.](report_assets/fig2_mithal_network.png) +*Figure 2: mithal.space — Network panel: 25 requests, 228 kB transferred, mostly CDN/library resources.* + +![mithal.space - Network panel filtered by "js".](report_assets/fig3_mithal_network_js.png) +*Figure 3: mithal.space — Network panel filtered by "js": scripts initiated by processor.js / contentscript.js, characteristic of a browser extension rather than the site itself.* + +

3.3 HTTPS / TLS

+ +The Security panel confirmed a valid, trusted certificate using TLS 1.3, with the modern hybrid post-quantum key exchange X25519MLKEM768, an ECDSA-with-SHA-256 server signature, and the AES_128_GCM cipher. The certificate was valid (17 May 2026 – 15 Sep 2026) and Certificate Transparency (SCT) verification passed. This is a strong, up-to-date HTTPS configuration. + +![mithal.space - Security panel.](report_assets/fig4_mithal_security.png) +*Figure 4: mithal.space — Security panel: TLS 1.3, X25519MLKEM768 key exchange, AES_128_GCM cipher, valid certificate.* + +

3.4 HTTP Headers

+ +The response for the main document listed roughly a dozen response headers, including a Referrer-Policy of strict-origin-when-cross-origin, which limits the referrer information leaked to other origins. No Content-Security-Policy or Strict-Transport-Security header was observed among the captured headers, which is a gap addressed in the recommendations below. + +![mithal.space - Request/response headers.](report_assets/fig5_mithal_headers.png) +*Figure 5: mithal.space — Request/response headers, including Referrer-Policy: strict-origin-when-cross-origin.* + +

4. Comparison with Other Search Engines

+ +mithal.space was compared with Google Search (inspected directly via DevTools) and, for additional context, DuckDuckGo (assessed from its publicly documented privacy practices rather than a live capture in this exercise). + +| Criterion | mithal.space (example.com) | Google.com | +|---|---|---| +| Cookies set on load | None observed (no cookies listed) | Multiple, across google.com, play.google.com, accounts.google.com | +| Network requests | 25 requests, ~228 kB transferred | 75 requests, ~238 kB transferred, 4.3 MB total resources | +| Third-party / telemetry calls | A few CDN/library scripts; extension content-scripts seen in the panel, not site code | Multiple log/ping endpoints with auth + hash parameters on nearly every load | +| TLS version | TLS 1.3 | TLS 1.3 | +| Key exchange | X25519MLKEM768 (post-quantum hybrid) | Not shown / standard ECDHE | +| Cipher | AES_128_GCM | AES_128_GCM | +| Response headers | ~12 headers, mostly standard (e.g. Referrer-Policy) | Large Client-Hints set (Sec-CH-UA-*, Sec-CH-Prefers-Color-Scheme, Sec-CH-RTT, Sec-CH-Downlink, etc.) plus Alt-Svc: h3 | +| Overall exposure | Low — minimal cookies, small footprint | High — broad cookie use, heavy telemetry, fingerprinting-capable headers | + +

Google Search

+ +Google's Cookies panel listed cookies set across google.com, play.google.com, and accounts.google.com. Its Network panel captured 75 requests and 4.3 MB of resources, including repeated "log?" and "ping" calls carrying authentication and hash parameters — consistent with telemetry/analytics traffic fired on nearly every page load. Its response headers included a large set of Client Hints (Sec-CH-UA-Platform, Sec-CH-UA-Model, Sec-CH-UA-Full-Version-List, Sec-CH-Downlink, Sec-CH-RTT, Sec-CH-Prefers-Color-Scheme, etc.). These headers let a server request granular device and browser details, which can contribute to fingerprinting if combined across visits. + +![google.com - Cookies in use panel.](report_assets/fig6_google_cookies.png) +*Figure 6: google.com — Cookies in use panel: cookies set across google.com, play.google.com and accounts.google.com.* + +![google.com - Security panel.](report_assets/fig7_google_security.png) +*Figure 7: google.com — Security panel: TLS 1.3 with many additional secure sub-origins (gstatic, accounts, play, extensions, etc.).* + +![google.com - Network panel.](report_assets/fig8_google_network.png) +*Figure 8: google.com — Network panel: 75 requests / 4.3 MB of resources, including recurring log/ping telemetry calls.* + +![google.com - Response headers.](report_assets/fig9_google_headers.png) +*Figure 9: google.com — Response headers: an extensive set of Accept-CH / Sec-CH-UA-* Client Hints headers plus Alt-Svc: h3.* + +

DuckDuckGo (for reference)

+ +DuckDuckGo is widely documented as not setting tracking cookies by default and not logging identifiable search queries. It is included here only as a general privacy-oriented reference point, since it was not captured in this DevTools session. + +Overall, mithal.space's footprint (few requests, no cookies, no telemetry pings) is closer to a privacy-conscious engine like DuckDuckGo than to Google, whose scale, cookie use, and Client-Hints headers give it materially more data-collection surface. + +

5. Recommended Security & Privacy Improvements for mithal.space

+ +1. **Add a Content-Security-Policy and HSTS header.** No CSP was observed in the captured response headers, so any injected or third-party script currently has broad ability to run on the page. A strict CSP (restricting script-src to self and explicitly trusted CDNs) plus Strict-Transport-Security with a long max-age and "preload" would harden the site against script injection and protocol-downgrade attacks. +2. **Self-host or add Subresource Integrity (SRI) to third-party scripts.** The site currently loads several libraries from external CDNs. Self-hosting them, or at minimum adding SRI hashes and crossorigin attributes, would prevent a compromised CDN from silently injecting malicious or tracking code, and would reduce the number of external parties the browser talks to. +3. **Prepare secure defaults for cookies and minimize Client Hints exposure.** mithal.space currently sets no cookies, which is good — but if cookies are introduced later (e.g. for search preferences), they should be scoped with Secure, HttpOnly, and SameSite=Strict/Lax flags. The site should also avoid opting into broad Accept-CH client-hint requests (as seen on Google), requesting only the specific hints it actually needs, to keep its fingerprinting surface minimal as the product grows. + +

6. Conclusion

+ +Based on this DevTools inspection, mithal.space demonstrates a privacy-friendly baseline: no cookies on load, a small and mostly first-party network footprint, and a modern, correctly configured TLS 1.3 setup. Its main gap relative to security best practice is the absence of hardening headers such as CSP and HSTS. Compared with Google, which sets multiple cookies, generates a much larger volume of telemetry-like traffic, and requests an extensive set of Client Hints, mithal.space collects and exposes considerably less user data. Implementing the three recommendations above would close most of the remaining gap between mithal.space and a best-practice privacy-preserving search engine. diff --git a/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.pdf b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.pdf new file mode 100644 index 0000000..5e73768 Binary files /dev/null and b/q3-privacy-assessment/Privacy_Assessment_Report_mithal.space.pdf differ diff --git a/q4-siem-log-analysis/README.md b/q4-siem-log-analysis/README.md new file mode 100644 index 0000000..4e2af8f --- /dev/null +++ b/q4-siem-log-analysis/README.md @@ -0,0 +1,134 @@ +# نظام SIEM مبسط — دليل التسليم + +## المحتويات +| الملف | الوظيفة | +|---|---| +| `siem_analyzer.py` | المحرك الرئيسي: يقرأ 3 مصادر سجلات، يكتشف الأنماط المشبوهة، يكتب `output/alerts.json` | +| `generate_sample_logs.py` | يولّد سجلات تجريبية (Web/Auth/Firewall) لتجربة النظام قبل التسليم | +| `dashboard.html` | لوحة المراقبة (HTML/CSS/JS) — تعرض التنبيهات وعناوين IP المشبوهة | +| `logs/` | مجلد السجلات الخام (المدخلات) | +| `output/alerts.json` | مخرجات التحليل (المخرج الذي تقرأه اللوحة) | + +--- + +## 1) المصادر الثلاثة المُختارة ولماذا + +| # | المصدر | الطبقة | الهجمات المكتشفة | +|---|---|---|---| +| 1 | **Web Server** (`access.log` بصيغة Nginx/Apache) | Application Layer | SQL Injection، Directory Traversal، Scanning/Fuzzing (كثرة 404/403 من نفس IP) | +| 2 | **Auth/OS** (`auth.log` بصيغة Linux SSH) | Endpoint/OS Layer | Brute Force، دخول ناجح بعد فشل متكرر | +| 3 | **Firewall** (`firewall.log` بصيغة iptables) | Network Layer | Port Scanning (تعدد المنافذ المحظورة من نفس IP) | + +اختيار هذه الطبقات الثلاث معًا (شبكة + نظام + تطبيق) يعطي رؤية شاملة تشبه أي SIEM حقيقي. + +## 2) طريقة التشغيل + +```bash +# 1. توليد سجلات تجريبية (أو استبدل logs/*.log بسجلاتك الحقيقية) +python3 generate_sample_logs.py + +# 2. تشغيل التحليل مرة واحدة +python3 siem_analyzer.py --once + +# أو تشغيل دوري (محاكاة عمل خدمة SIEM حية) كل 30 ثانية +python3 siem_analyzer.py --watch 30 + +# 3. تشغيل خادم محلي بسيط لعرض اللوحة (ضروري كي تستطيع اللوحة قراءة alerts.json عبر fetch) +python3 -m http.server 8000 + +# 4. افتح المتصفح على: +http://localhost:8000/dashboard.html +``` + +> ملاحظة: إذا فتحت `dashboard.html` مباشرة (بدون خادم)، أضفنا زر **"تحميل alerts.json يدويًا"** في اللوحة كحل بديل يعمل بدون أي خادم. + +لاستخدام سجلاتك الحقيقية بدلاً من التجريبية، عدّل المسارات في أعلى `siem_analyzer.py`: +```python +CONFIG = { + "web_log_path": "/var/log/nginx/access.log", + "auth_log_path": "/var/log/auth.log", + "firewall_log_path": "/var/log/iptables.log", + ... +} +``` + +## 3) منطق الكشف (Detection Logic) باختصار + +- **SQL Injection / Traversal**: تعابير قياسية (Regex) تبحث عن `UNION SELECT`، `OR 1=1`، `../` ضمن الـ URL المطلوب. +- **Scanning عبر الويب**: عدّاد لكل IP لعدد أكواد 404/403؛ إذا تجاوز الحد (15 افتراضيًا) → تنبيه. +- **Brute Force**: عدّاد محاولات `Failed password` لكل IP خلال الملف؛ إذا تجاوز 5 محاولات → تنبيه، ويُرفع لمستوى "حرج" إذا نجح الدخول بعدها. +- **Port Scanning**: تجميع المنافذ الفريدة (`set`) التي حاول كل IP الوصول إليها وتم رفضها (`DROP/REJECT/BLOCK`)؛ إذا تجاوزت 15 منفذًا → تنبيه. + +كل الحدود (Thresholds) قابلة للتعديل من قاموس `CONFIG` أعلى ملف `siem_analyzer.py`. + +## 4) تصميم الـ Dashboard + +- بطاقات إحصائية علوية (إجمالي التنبيهات، حرجة، عالية، IP مشبوهة). +- جدول التنبيهات كاملاً مرتب حسب الخطورة. +- جدول عناوين IP المشبوهة مع درجة الخطورة (Score) المحسوبة من وزن كل تنبيه. +- رسم بياني بسيط (أعمدة) لعدد التنبيهات حسب المصدر. +- تحديث تلقائي كل 10 ثوانٍ عبر `fetch`، بالإضافة لزر تحديث يدوي وزر رفع ملف JSON يدويًا. + +--- + +## 5) النشر على غيمة (Cloud) باستخدام Block Storage — الجزء المطلوب في السؤال الثالث + +### الفكرة العامة +الهدف من استخدام **Block Storage** هنا هو فصل بيانات السجلات (Logs) عن دورة حياة الخادم (VM)، بحيث: +- إذا تم حذف/إعادة بناء الخادم، لا تُفقد السجلات التاريخية. +- يمكن أخذ نسخ احتياطية (Snapshots) لوحدة التخزين بشكل مستقل عن الخادم. +- يمكن فصل الوحدة وتوصيلها بخادم آخر (مثلاً خادم تحليل مخصص) دون نقل بيانات فعليًا. + +### خطوات النشر (عامة، تنطبق على أغلب مزودي الغيمة) + +1. **إنشاء خادم افتراضي (VM/Instance)** لتشغيل السكربتات ولوحة الـ Dashboard (يكفي حجم صغير: 1-2 vCPU، 1-2GB RAM). + +2. **إنشاء وحدة Block Storage** منفصلة (مثلاً 20-50GB حسب حجم السجلات المتوقع) وربطها (Attach) بالخادم. + +3. **تهيئة ووصل الوحدة (Mount)** داخل الخادم: + ```bash + sudo mkfs.ext4 /dev/vdb # تهيئة الوحدة (مرة واحدة فقط) + sudo mkdir -p /mnt/siem-storage + sudo mount /dev/vdb /mnt/siem-storage + echo "/dev/vdb /mnt/siem-storage ext4 defaults 0 2" | sudo tee -a /etc/fstab # لضمان الوصل التلقائي بعد إعادة التشغيل + ``` + +4. **نقل مجلدي `logs/` و `output/` إلى وحدة التخزين**، وتحديث المسارات في `CONFIG` داخل `siem_analyzer.py`: + ```python + CONFIG = { + "web_log_path": "/mnt/siem-storage/logs/access.log", + "auth_log_path": "/mnt/siem-storage/logs/auth.log", + "firewall_log_path": "/mnt/siem-storage/logs/firewall.log", + "output_path": "/mnt/siem-storage/output/alerts.json", + ... + } + ``` + +5. **تشغيل التحليل كخدمة دائمة (systemd)** بدلاً من تشغيله يدويًا، مثال `siem-analyzer.service`: + ```ini + [Unit] + Description=SIEM Log Analyzer + After=network.target + + [Service] + ExecStart=/usr/bin/python3 /opt/siem/siem_analyzer.py --watch 60 + Restart=always + User=siem + + [Install] + WantedBy=multi-user.target + ``` + ```bash + sudo systemctl enable --now siem-analyzer + ``` + +6. **تشغيل الـ Dashboard عبر خادم ويب حقيقي** (بدلاً من `http.server`) مثل Nginx، بحيث يخدم: + - `dashboard.html` كصفحة ثابتة. + - `output/alerts.json` (الموجود فعليًا على وحدة الـ Block Storage المُوصولة) كملف بيانات يُقرأ عبر `fetch`. + +7. **(اختياري) نسخ احتياطي دوري**: جدولة Snapshot يومي لوحدة الـ Block Storage عبر لوحة تحكم مزود الغيمة، لحفظ تاريخ السجلات والتنبيهات بشكل مستقل عن الخادم نفسه. + +### لماذا Block Storage تحديدًا (وليس تخزين محلي على القرص الافتراضي للخادم)؟ +- **الاستمرارية (Persistence)**: تخزين القرص الافتراضي المرفق افتراضيًا بالخادم (Root Disk) قد يُفقد عند حذف الخادم؛ Block Storage وحدة مستقلة يمكن الاحتفاظ بها. +- **قابلية التوسع (Scalability)**: يمكن زيادة حجم الوحدة لاحقًا دون التأثير على الخادم نفسه، مهم لأن حجم السجلات يكبر مع الوقت. +- **قابلية النقل**: يمكن فصل الوحدة وربطها بخادم تحليل آخر (مثلاً خادم أقوى لتشغيل تحليل أعمق) دون نسخ نيوتيرا (TB) من البيانات عبر الشبكة. diff --git a/q4-siem-log-analysis/access.log b/q4-siem-log-analysis/access.log new file mode 100644 index 0000000..c77a5fc --- /dev/null +++ b/q4-siem-log-analysis/access.log @@ -0,0 +1,455 @@ +192.168.1.104 - - [27/Jul/2026:16:14:46 +0000] "GET /products HTTP/1.1" 200 333 +192.168.1.38 - - [27/Jul/2026:16:10:29 +0000] "GET /products HTTP/1.1" 404 1654 +192.168.1.144 - - [27/Jul/2026:16:15:32 +0000] "GET /about HTTP/1.1" 404 4472 +192.168.1.131 - - [27/Jul/2026:16:18:37 +0000] "GET / HTTP/1.1" 200 4337 +192.168.1.109 - - [27/Jul/2026:16:20:34 +0000] "GET /about HTTP/1.1" 404 1319 +192.168.1.114 - - [27/Jul/2026:16:08:35 +0000] "GET /index.html HTTP/1.1" 304 4613 +192.168.1.167 - - [27/Jul/2026:15:42:29 +0000] "GET /login HTTP/1.1" 404 2531 +192.168.1.247 - - [27/Jul/2026:15:46:43 +0000] "GET /api/users HTTP/1.1" 200 788 +192.168.1.5 - - [27/Jul/2026:16:09:14 +0000] "GET / HTTP/1.1" 404 2766 +192.168.1.41 - - [27/Jul/2026:16:31:45 +0000] "GET /about HTTP/1.1" 200 3625 +192.168.1.99 - - [27/Jul/2026:15:40:31 +0000] "GET /products HTTP/1.1" 200 2771 +192.168.1.35 - - [27/Jul/2026:16:17:57 +0000] "GET /index.html HTTP/1.1" 304 2553 +192.168.1.118 - - [27/Jul/2026:15:40:50 +0000] "GET /products HTTP/1.1" 404 4295 +192.168.1.37 - - [27/Jul/2026:15:58:27 +0000] "GET /login HTTP/1.1" 304 3532 +45.155.205.7 - - [27/Jul/2026:16:23:58 +0000] "GET /wp-admin/196.php HTTP/1.1" 404 200 +192.168.1.106 - - [27/Jul/2026:16:22:31 +0000] "GET /about HTTP/1.1" 200 1016 +192.168.1.132 - - [27/Jul/2026:15:53:03 +0000] "GET /about HTTP/1.1" 304 4065 +192.168.1.218 - - [27/Jul/2026:16:16:25 +0000] "GET /index.html HTTP/1.1" 200 3052 +192.168.1.112 - - [27/Jul/2026:16:29:35 +0000] "GET /about HTTP/1.1" 404 2835 +192.168.1.18 - - [27/Jul/2026:16:29:36 +0000] "GET /products HTTP/1.1" 304 2835 +192.168.1.119 - - [27/Jul/2026:16:22:25 +0000] "GET /login HTTP/1.1" 200 1701 +192.168.1.223 - - [27/Jul/2026:15:36:47 +0000] "GET /login HTTP/1.1" 304 4366 +192.168.1.139 - - [27/Jul/2026:15:59:45 +0000] "GET /products HTTP/1.1" 304 3946 +192.168.1.56 - - [27/Jul/2026:16:25:30 +0000] "GET /index.html HTTP/1.1" 304 236 +192.168.1.90 - - [27/Jul/2026:16:18:51 +0000] "GET / HTTP/1.1" 200 2780 +192.168.1.183 - - [27/Jul/2026:16:12:28 +0000] "GET /about HTTP/1.1" 200 2325 +203.0.113.45 - - [27/Jul/2026:16:26:07 +0000] "GET /products?id=1 OR 1=1 HTTP/1.1" 500 512 +192.168.1.90 - - [27/Jul/2026:16:01:14 +0000] "GET /index.html HTTP/1.1" 404 1288 +192.168.1.111 - - [27/Jul/2026:15:39:27 +0000] "GET /login HTTP/1.1" 200 3654 +192.168.1.232 - - [27/Jul/2026:15:58:55 +0000] "GET /api/users HTTP/1.1" 304 1259 +192.168.1.108 - - [27/Jul/2026:16:18:05 +0000] "GET / HTTP/1.1" 304 447 +45.155.205.7 - - [27/Jul/2026:16:28:57 +0000] "GET /wp-admin/560.php HTTP/1.1" 404 200 +192.168.1.244 - - [27/Jul/2026:15:34:22 +0000] "GET /products HTTP/1.1" 200 4921 +192.168.1.161 - - [27/Jul/2026:15:34:34 +0000] "GET /about HTTP/1.1" 200 609 +192.168.1.75 - - [27/Jul/2026:15:55:10 +0000] "GET /about HTTP/1.1" 304 781 +192.168.1.4 - - [27/Jul/2026:15:57:32 +0000] "GET /products HTTP/1.1" 200 2460 +192.168.1.167 - - [27/Jul/2026:16:06:06 +0000] "GET /api/users HTTP/1.1" 304 2416 +192.168.1.115 - - [27/Jul/2026:16:18:37 +0000] "GET /index.html HTTP/1.1" 200 4501 +192.168.1.37 - - [27/Jul/2026:15:56:43 +0000] "GET /login HTTP/1.1" 200 3672 +192.168.1.210 - - [27/Jul/2026:16:07:26 +0000] "GET /index.html HTTP/1.1" 200 590 +192.168.1.141 - - [27/Jul/2026:16:10:12 +0000] "GET /api/users HTTP/1.1" 200 603 +192.168.1.50 - - [27/Jul/2026:16:26:32 +0000] "GET /api/users HTTP/1.1" 304 4002 +192.168.1.22 - - [27/Jul/2026:15:42:16 +0000] "GET / HTTP/1.1" 200 324 +192.168.1.122 - - [27/Jul/2026:15:42:24 +0000] "GET /login HTTP/1.1" 404 1163 +192.168.1.28 - - [27/Jul/2026:15:53:08 +0000] "GET /index.html HTTP/1.1" 404 2073 +192.168.1.236 - - [27/Jul/2026:16:19:59 +0000] "GET /index.html HTTP/1.1" 304 1321 +192.168.1.9 - - [27/Jul/2026:16:03:41 +0000] "GET /login HTTP/1.1" 404 2616 +192.168.1.249 - - [27/Jul/2026:16:10:54 +0000] "GET /index.html HTTP/1.1" 200 2802 +192.168.1.26 - - [27/Jul/2026:16:26:21 +0000] "GET /index.html HTTP/1.1" 200 1735 +192.168.1.242 - - [27/Jul/2026:16:16:15 +0000] "GET /about HTTP/1.1" 304 1035 +192.168.1.160 - - [27/Jul/2026:15:50:29 +0000] "GET /api/users HTTP/1.1" 304 2154 +192.168.1.157 - - [27/Jul/2026:16:10:47 +0000] "GET / HTTP/1.1" 304 2781 +192.168.1.237 - - [27/Jul/2026:16:00:22 +0000] "GET /login HTTP/1.1" 200 2636 +45.155.205.7 - - [27/Jul/2026:16:24:52 +0000] "GET /wp-admin/524.php HTTP/1.1" 404 200 +192.168.1.20 - - [27/Jul/2026:16:20:53 +0000] "GET /api/users HTTP/1.1" 200 2130 +192.168.1.201 - - [27/Jul/2026:16:15:45 +0000] "GET /about HTTP/1.1" 200 2091 +192.168.1.88 - - [27/Jul/2026:16:26:47 +0000] "GET /products HTTP/1.1" 200 331 +192.168.1.129 - - [27/Jul/2026:16:01:42 +0000] "GET /about HTTP/1.1" 304 3138 +192.168.1.154 - - [27/Jul/2026:15:43:47 +0000] "GET /products HTTP/1.1" 304 202 +192.168.1.117 - - [27/Jul/2026:16:16:03 +0000] "GET /about HTTP/1.1" 304 2266 +192.168.1.7 - - [27/Jul/2026:16:31:29 +0000] "GET /login HTTP/1.1" 200 1944 +192.168.1.216 - - [27/Jul/2026:16:24:13 +0000] "GET /login HTTP/1.1" 404 2867 +203.0.113.45 - - [27/Jul/2026:16:32:45 +0000] "GET /products?id=1 OR 1=1 HTTP/1.1" 500 512 +192.168.1.12 - - [27/Jul/2026:15:57:48 +0000] "GET /api/users HTTP/1.1" 304 3067 +192.168.1.98 - - [27/Jul/2026:15:40:11 +0000] "GET /index.html HTTP/1.1" 200 2498 +192.168.1.218 - - [27/Jul/2026:15:48:32 +0000] "GET / HTTP/1.1" 404 258 +192.168.1.144 - - [27/Jul/2026:16:15:52 +0000] "GET /api/users HTTP/1.1" 200 3426 +192.168.1.163 - - [27/Jul/2026:15:54:58 +0000] "GET /login HTTP/1.1" 304 3888 +192.168.1.190 - - [27/Jul/2026:15:37:58 +0000] "GET /index.html HTTP/1.1" 200 3034 +192.168.1.180 - - [27/Jul/2026:16:30:03 +0000] "GET /about HTTP/1.1" 200 2367 +192.168.1.231 - - [27/Jul/2026:15:53:33 +0000] "GET /about HTTP/1.1" 304 1000 +192.168.1.207 - - [27/Jul/2026:15:42:53 +0000] "GET /index.html HTTP/1.1" 200 4427 +192.168.1.232 - - [27/Jul/2026:16:30:38 +0000] "GET /api/users HTTP/1.1" 200 724 +192.168.1.106 - - [27/Jul/2026:16:32:52 +0000] "GET / HTTP/1.1" 200 4033 +192.168.1.172 - - [27/Jul/2026:16:24:48 +0000] "GET /products HTTP/1.1" 304 3170 +192.168.1.90 - - [27/Jul/2026:16:00:15 +0000] "GET /login HTTP/1.1" 200 1261 +192.168.1.242 - - [27/Jul/2026:15:55:44 +0000] "GET / HTTP/1.1" 404 2782 +192.168.1.103 - - [27/Jul/2026:15:33:12 +0000] "GET /api/users HTTP/1.1" 304 345 +192.168.1.17 - - [27/Jul/2026:16:02:47 +0000] "GET / HTTP/1.1" 200 4235 +192.168.1.125 - - [27/Jul/2026:16:02:07 +0000] "GET /api/users HTTP/1.1" 404 4476 +192.168.1.185 - - [27/Jul/2026:16:31:26 +0000] "GET /about HTTP/1.1" 304 2232 +192.168.1.23 - - [27/Jul/2026:15:51:42 +0000] "GET /index.html HTTP/1.1" 200 4460 +45.155.205.7 - - [27/Jul/2026:16:26:48 +0000] "GET /wp-admin/215.php HTTP/1.1" 404 200 +45.155.205.7 - - [27/Jul/2026:16:28:39 +0000] "GET /wp-admin/789.php HTTP/1.1" 404 200 +192.168.1.92 - - [27/Jul/2026:16:22:08 +0000] "GET /api/users HTTP/1.1" 200 3725 +192.168.1.72 - - [27/Jul/2026:16:27:49 +0000] "GET /products HTTP/1.1" 404 4416 +192.168.1.24 - - [27/Jul/2026:15:58:09 +0000] "GET /login HTTP/1.1" 200 4047 +192.168.1.233 - - [27/Jul/2026:16:26:18 +0000] "GET / HTTP/1.1" 304 4238 +192.168.1.95 - - [27/Jul/2026:16:13:49 +0000] "GET /login HTTP/1.1" 200 4750 +192.168.1.35 - - [27/Jul/2026:16:27:30 +0000] "GET /api/users HTTP/1.1" 304 3606 +192.168.1.171 - - [27/Jul/2026:16:18:44 +0000] "GET /login HTTP/1.1" 200 538 +45.155.205.7 - - [27/Jul/2026:16:26:14 +0000] "GET /wp-admin/494.php HTTP/1.1" 404 200 +192.168.1.26 - - [27/Jul/2026:16:10:34 +0000] "GET /products HTTP/1.1" 200 274 +192.168.1.210 - - [27/Jul/2026:15:44:50 +0000] "GET /index.html HTTP/1.1" 200 3610 +192.168.1.151 - - [27/Jul/2026:15:42:17 +0000] "GET /index.html HTTP/1.1" 200 666 +192.168.1.244 - - [27/Jul/2026:16:21:09 +0000] "GET /api/users HTTP/1.1" 200 2988 +192.168.1.17 - - [27/Jul/2026:15:53:55 +0000] "GET /products HTTP/1.1" 200 4729 +192.168.1.41 - - [27/Jul/2026:16:17:36 +0000] "GET /products HTTP/1.1" 200 1905 +203.0.113.45 - - [27/Jul/2026:16:29:56 +0000] "GET /search?q=SELECT * FROM accounts HTTP/1.1" 500 512 +45.155.205.7 - - [27/Jul/2026:16:28:18 +0000] "GET /wp-admin/819.php HTTP/1.1" 404 200 +192.168.1.124 - - [27/Jul/2026:15:46:04 +0000] "GET /api/users HTTP/1.1" 200 3634 +192.168.1.145 - - [27/Jul/2026:15:34:46 +0000] "GET /login HTTP/1.1" 200 3569 +45.155.205.7 - - [27/Jul/2026:16:23:19 +0000] "GET /wp-admin/127.php HTTP/1.1" 404 200 +192.168.1.171 - - [27/Jul/2026:16:21:51 +0000] "GET /login HTTP/1.1" 304 538 +192.168.1.81 - - [27/Jul/2026:16:26:39 +0000] "GET /api/users HTTP/1.1" 200 2279 +192.168.1.47 - - [27/Jul/2026:16:02:11 +0000] "GET /about HTTP/1.1" 200 285 +192.168.1.226 - - [27/Jul/2026:16:04:50 +0000] "GET /index.html HTTP/1.1" 304 1097 +192.168.1.175 - - [27/Jul/2026:15:57:23 +0000] "GET /login HTTP/1.1" 200 753 +192.168.1.92 - - [27/Jul/2026:15:57:15 +0000] "GET /login HTTP/1.1" 200 4358 +192.168.1.67 - - [27/Jul/2026:16:29:56 +0000] "GET /api/users HTTP/1.1" 200 1705 +192.168.1.57 - - [27/Jul/2026:16:30:33 +0000] "GET /api/users HTTP/1.1" 200 2628 +192.168.1.202 - - [27/Jul/2026:15:51:43 +0000] "GET / HTTP/1.1" 200 4925 +45.155.205.7 - - [27/Jul/2026:16:26:51 +0000] "GET /wp-admin/504.php HTTP/1.1" 404 200 +192.168.1.102 - - [27/Jul/2026:16:20:39 +0000] "GET /login HTTP/1.1" 200 2976 +192.168.1.125 - - [27/Jul/2026:15:35:37 +0000] "GET /products HTTP/1.1" 200 2736 +192.168.1.131 - - [27/Jul/2026:16:29:43 +0000] "GET /api/users HTTP/1.1" 200 3023 +192.168.1.175 - - [27/Jul/2026:16:23:23 +0000] "GET /about HTTP/1.1" 404 3061 +192.168.1.99 - - [27/Jul/2026:15:37:06 +0000] "GET /about HTTP/1.1" 404 3839 +192.168.1.204 - - [27/Jul/2026:15:42:44 +0000] "GET /index.html HTTP/1.1" 200 3905 +192.168.1.33 - - [27/Jul/2026:15:50:46 +0000] "GET /api/users HTTP/1.1" 200 3797 +192.168.1.246 - - [27/Jul/2026:16:03:29 +0000] "GET /products HTTP/1.1" 304 3535 +192.168.1.161 - - [27/Jul/2026:16:11:53 +0000] "GET /index.html HTTP/1.1" 200 2913 +192.168.1.186 - - [27/Jul/2026:16:20:47 +0000] "GET /login HTTP/1.1" 200 1997 +192.168.1.105 - - [27/Jul/2026:15:59:27 +0000] "GET /products HTTP/1.1" 200 3524 +45.155.205.7 - - [27/Jul/2026:16:30:15 +0000] "GET /wp-admin/816.php HTTP/1.1" 404 200 +192.168.1.35 - - [27/Jul/2026:15:38:00 +0000] "GET / HTTP/1.1" 304 4744 +192.168.1.143 - - [27/Jul/2026:16:08:41 +0000] "GET /api/users HTTP/1.1" 200 1886 +192.168.1.20 - - [27/Jul/2026:15:53:11 +0000] "GET /login HTTP/1.1" 200 1735 +192.168.1.75 - - [27/Jul/2026:15:48:27 +0000] "GET /api/users HTTP/1.1" 200 1278 +192.168.1.198 - - [27/Jul/2026:16:12:56 +0000] "GET /index.html HTTP/1.1" 304 908 +192.168.1.244 - - [27/Jul/2026:16:19:22 +0000] "GET /products HTTP/1.1" 200 1368 +192.168.1.111 - - [27/Jul/2026:16:27:41 +0000] "GET /api/users HTTP/1.1" 200 1362 +192.168.1.20 - - [27/Jul/2026:15:34:19 +0000] "GET /api/users HTTP/1.1" 200 4928 +192.168.1.174 - - [27/Jul/2026:16:17:35 +0000] "GET /products HTTP/1.1" 304 2024 +192.168.1.96 - - [27/Jul/2026:15:37:52 +0000] "GET /about HTTP/1.1" 304 2505 +192.168.1.84 - - [27/Jul/2026:16:06:57 +0000] "GET /products HTTP/1.1" 304 858 +192.168.1.247 - - [27/Jul/2026:15:40:18 +0000] "GET /login HTTP/1.1" 404 3958 +192.168.1.127 - - [27/Jul/2026:15:51:09 +0000] "GET /index.html HTTP/1.1" 200 4993 +192.168.1.20 - - [27/Jul/2026:15:50:30 +0000] "GET / HTTP/1.1" 200 4975 +198.51.100.23 - - [27/Jul/2026:16:26:33 +0000] "GET /download?file=../../../../etc/passwd HTTP/1.1" 403 300 +192.168.1.87 - - [27/Jul/2026:16:01:22 +0000] "GET /login HTTP/1.1" 200 1161 +192.168.1.9 - - [27/Jul/2026:15:37:53 +0000] "GET /products HTTP/1.1" 404 1634 +192.168.1.195 - - [27/Jul/2026:15:45:25 +0000] "GET /login HTTP/1.1" 200 2762 +192.168.1.159 - - [27/Jul/2026:16:26:32 +0000] "GET /index.html HTTP/1.1" 200 4109 +192.168.1.194 - - [27/Jul/2026:16:19:40 +0000] "GET /api/users HTTP/1.1" 200 3442 +45.155.205.7 - - [27/Jul/2026:16:24:15 +0000] "GET /wp-admin/652.php HTTP/1.1" 404 200 +192.168.1.23 - - [27/Jul/2026:16:11:16 +0000] "GET /index.html HTTP/1.1" 404 1564 +192.168.1.89 - - [27/Jul/2026:15:54:45 +0000] "GET /index.html HTTP/1.1" 200 1123 +192.168.1.29 - - [27/Jul/2026:15:50:02 +0000] "GET /login HTTP/1.1" 200 4530 +192.168.1.201 - - [27/Jul/2026:15:55:11 +0000] "GET /login HTTP/1.1" 200 1960 +192.168.1.94 - - [27/Jul/2026:16:15:36 +0000] "GET / HTTP/1.1" 404 2283 +45.155.205.7 - - [27/Jul/2026:16:23:29 +0000] "GET /wp-admin/651.php HTTP/1.1" 404 200 +192.168.1.51 - - [27/Jul/2026:15:53:01 +0000] "GET /index.html HTTP/1.1" 404 4064 +192.168.1.138 - - [27/Jul/2026:16:07:28 +0000] "GET /login HTTP/1.1" 200 4163 +192.168.1.82 - - [27/Jul/2026:16:23:44 +0000] "GET /api/users HTTP/1.1" 200 2432 +192.168.1.59 - - [27/Jul/2026:16:05:04 +0000] "GET /index.html HTTP/1.1" 200 4208 +192.168.1.92 - - [27/Jul/2026:15:42:06 +0000] "GET /products HTTP/1.1" 404 4062 +192.168.1.103 - - [27/Jul/2026:15:55:09 +0000] "GET /products HTTP/1.1" 200 767 +45.155.205.7 - - [27/Jul/2026:16:28:37 +0000] "GET /wp-admin/274.php HTTP/1.1" 404 200 +192.168.1.63 - - [27/Jul/2026:15:57:02 +0000] "GET /login HTTP/1.1" 304 3971 +192.168.1.98 - - [27/Jul/2026:16:33:06 +0000] "GET /api/users HTTP/1.1" 200 4941 +192.168.1.231 - - [27/Jul/2026:16:27:06 +0000] "GET /products HTTP/1.1" 200 4876 +192.168.1.79 - - [27/Jul/2026:16:05:08 +0000] "GET /about HTTP/1.1" 200 1276 +198.51.100.23 - - [27/Jul/2026:16:32:15 +0000] "GET /download?file=../../../../etc/passwd HTTP/1.1" 403 300 +45.155.205.7 - - [27/Jul/2026:16:23:29 +0000] "GET /wp-admin/238.php HTTP/1.1" 404 200 +192.168.1.12 - - [27/Jul/2026:15:39:55 +0000] "GET /products HTTP/1.1" 200 1793 +192.168.1.205 - - [27/Jul/2026:16:01:55 +0000] "GET /about HTTP/1.1" 200 4598 +192.168.1.38 - - [27/Jul/2026:16:02:49 +0000] "GET /products HTTP/1.1" 304 4517 +192.168.1.226 - - [27/Jul/2026:16:21:36 +0000] "GET /about HTTP/1.1" 200 792 +192.168.1.203 - - [27/Jul/2026:16:03:56 +0000] "GET /api/users HTTP/1.1" 304 3811 +192.168.1.86 - - [27/Jul/2026:16:06:17 +0000] "GET /index.html HTTP/1.1" 200 4613 +192.168.1.232 - - [27/Jul/2026:16:18:26 +0000] "GET /api/users HTTP/1.1" 200 2426 +45.155.205.7 - - [27/Jul/2026:16:28:45 +0000] "GET /wp-admin/222.php HTTP/1.1" 404 200 +192.168.1.116 - - [27/Jul/2026:16:19:25 +0000] "GET /login HTTP/1.1" 200 484 +192.168.1.193 - - [27/Jul/2026:15:45:42 +0000] "GET /products HTTP/1.1" 200 520 +192.168.1.60 - - [27/Jul/2026:16:10:37 +0000] "GET /index.html HTTP/1.1" 200 1572 +192.168.1.223 - - [27/Jul/2026:15:52:19 +0000] "GET /index.html HTTP/1.1" 304 3603 +192.168.1.167 - - [27/Jul/2026:16:01:39 +0000] "GET /products HTTP/1.1" 304 3301 +192.168.1.83 - - [27/Jul/2026:15:40:21 +0000] "GET /login HTTP/1.1" 200 3436 +192.168.1.25 - - [27/Jul/2026:16:06:31 +0000] "GET /about HTTP/1.1" 200 3500 +192.168.1.194 - - [27/Jul/2026:16:26:05 +0000] "GET /login HTTP/1.1" 200 1630 +192.168.1.94 - - [27/Jul/2026:15:54:52 +0000] "GET /products HTTP/1.1" 200 2040 +192.168.1.65 - - [27/Jul/2026:16:18:14 +0000] "GET /api/users HTTP/1.1" 200 3547 +192.168.1.206 - - [27/Jul/2026:15:37:04 +0000] "GET /about HTTP/1.1" 304 2373 +192.168.1.30 - - [27/Jul/2026:16:10:49 +0000] "GET /products HTTP/1.1" 200 4965 +192.168.1.181 - - [27/Jul/2026:16:04:38 +0000] "GET /about HTTP/1.1" 200 1481 +192.168.1.58 - - [27/Jul/2026:16:29:46 +0000] "GET /index.html HTTP/1.1" 404 538 +192.168.1.55 - - [27/Jul/2026:15:34:31 +0000] "GET / HTTP/1.1" 200 3614 +192.168.1.231 - - [27/Jul/2026:16:06:29 +0000] "GET / HTTP/1.1" 304 2156 +192.168.1.4 - - [27/Jul/2026:16:06:26 +0000] "GET /login HTTP/1.1" 404 1149 +45.155.205.7 - - [27/Jul/2026:16:26:37 +0000] "GET /wp-admin/625.php HTTP/1.1" 404 200 +192.168.1.83 - - [27/Jul/2026:15:58:20 +0000] "GET /about HTTP/1.1" 200 4172 +45.155.205.7 - - [27/Jul/2026:16:25:51 +0000] "GET /wp-admin/729.php HTTP/1.1" 404 200 +192.168.1.79 - - [27/Jul/2026:16:18:02 +0000] "GET /about HTTP/1.1" 200 4754 +203.0.113.45 - - [27/Jul/2026:16:29:53 +0000] "GET /login?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 500 512 +192.168.1.115 - - [27/Jul/2026:16:07:46 +0000] "GET /products HTTP/1.1" 200 4554 +192.168.1.137 - - [27/Jul/2026:16:04:37 +0000] "GET /products HTTP/1.1" 404 1957 +192.168.1.88 - - [27/Jul/2026:16:32:57 +0000] "GET /index.html HTTP/1.1" 200 4414 +192.168.1.13 - - [27/Jul/2026:16:17:59 +0000] "GET /login HTTP/1.1" 200 4693 +192.168.1.189 - - [27/Jul/2026:15:54:42 +0000] "GET /index.html HTTP/1.1" 200 2467 +192.168.1.131 - - [27/Jul/2026:15:41:26 +0000] "GET /api/users HTTP/1.1" 200 3749 +45.155.205.7 - - [27/Jul/2026:16:25:23 +0000] "GET /wp-admin/680.php HTTP/1.1" 404 200 +192.168.1.180 - - [27/Jul/2026:16:29:02 +0000] "GET / HTTP/1.1" 304 3928 +192.168.1.203 - - [27/Jul/2026:16:10:46 +0000] "GET / HTTP/1.1" 304 2374 +192.168.1.250 - - [27/Jul/2026:16:07:10 +0000] "GET /api/users HTTP/1.1" 200 4670 +192.168.1.12 - - [27/Jul/2026:15:54:51 +0000] "GET /about HTTP/1.1" 200 4593 +192.168.1.234 - - [27/Jul/2026:15:47:34 +0000] "GET /products HTTP/1.1" 200 2188 +192.168.1.62 - - [27/Jul/2026:16:21:20 +0000] "GET / HTTP/1.1" 404 4369 +192.168.1.201 - - [27/Jul/2026:15:51:44 +0000] "GET /login HTTP/1.1" 200 1314 +192.168.1.160 - - [27/Jul/2026:15:41:09 +0000] "GET /login HTTP/1.1" 404 670 +192.168.1.45 - - [27/Jul/2026:16:17:45 +0000] "GET /about HTTP/1.1" 304 2943 +192.168.1.193 - - [27/Jul/2026:15:51:55 +0000] "GET /about HTTP/1.1" 304 205 +192.168.1.191 - - [27/Jul/2026:15:55:18 +0000] "GET / HTTP/1.1" 404 1783 +192.168.1.17 - - [27/Jul/2026:15:33:21 +0000] "GET /login HTTP/1.1" 304 4829 +45.155.205.7 - - [27/Jul/2026:16:23:48 +0000] "GET /wp-admin/466.php HTTP/1.1" 404 200 +192.168.1.45 - - [27/Jul/2026:16:31:29 +0000] "GET /index.html HTTP/1.1" 304 1255 +192.168.1.228 - - [27/Jul/2026:15:56:05 +0000] "GET / HTTP/1.1" 200 2824 +192.168.1.207 - - [27/Jul/2026:16:30:14 +0000] "GET /login HTTP/1.1" 200 2601 +198.51.100.23 - - [27/Jul/2026:16:24:03 +0000] "GET /view?page=..%2f..%2f..%2fetc%2fpasswd HTTP/1.1" 403 300 +192.168.1.117 - - [27/Jul/2026:16:09:27 +0000] "GET /index.html HTTP/1.1" 200 4979 +192.168.1.162 - - [27/Jul/2026:15:55:30 +0000] "GET /products HTTP/1.1" 404 3190 +192.168.1.161 - - [27/Jul/2026:15:34:12 +0000] "GET /login HTTP/1.1" 200 3564 +192.168.1.47 - - [27/Jul/2026:15:44:32 +0000] "GET /api/users HTTP/1.1" 404 3790 +192.168.1.164 - - [27/Jul/2026:16:01:21 +0000] "GET /index.html HTTP/1.1" 200 2736 +192.168.1.126 - - [27/Jul/2026:15:52:13 +0000] "GET /api/users HTTP/1.1" 200 2932 +192.168.1.241 - - [27/Jul/2026:15:47:13 +0000] "GET /products HTTP/1.1" 200 2203 +192.168.1.151 - - [27/Jul/2026:15:58:26 +0000] "GET /about HTTP/1.1" 200 314 +45.155.205.7 - - [27/Jul/2026:16:23:25 +0000] "GET /wp-admin/24.php HTTP/1.1" 404 200 +192.168.1.220 - - [27/Jul/2026:15:42:01 +0000] "GET /products HTTP/1.1" 200 2071 +192.168.1.199 - - [27/Jul/2026:16:22:27 +0000] "GET /index.html HTTP/1.1" 200 4136 +203.0.113.45 - - [27/Jul/2026:16:25:23 +0000] "GET /login?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 500 512 +45.155.205.7 - - [27/Jul/2026:16:32:30 +0000] "GET /wp-admin/554.php HTTP/1.1" 404 200 +192.168.1.191 - - [27/Jul/2026:15:59:48 +0000] "GET /about HTTP/1.1" 200 2080 +192.168.1.187 - - [27/Jul/2026:16:05:07 +0000] "GET /api/users HTTP/1.1" 200 1080 +192.168.1.16 - - [27/Jul/2026:16:26:27 +0000] "GET /products HTTP/1.1" 304 2936 +192.168.1.201 - - [27/Jul/2026:16:10:03 +0000] "GET /products HTTP/1.1" 200 4354 +192.168.1.23 - - [27/Jul/2026:16:08:03 +0000] "GET /products HTTP/1.1" 200 4631 +45.155.205.7 - - [27/Jul/2026:16:31:52 +0000] "GET /wp-admin/674.php HTTP/1.1" 404 200 +192.168.1.161 - - [27/Jul/2026:16:29:00 +0000] "GET /products HTTP/1.1" 200 349 +192.168.1.62 - - [27/Jul/2026:16:07:00 +0000] "GET / HTTP/1.1" 404 694 +192.168.1.192 - - [27/Jul/2026:16:19:24 +0000] "GET /api/users HTTP/1.1" 404 1765 +192.168.1.91 - - [27/Jul/2026:15:50:24 +0000] "GET /api/users HTTP/1.1" 200 4240 +192.168.1.108 - - [27/Jul/2026:16:03:46 +0000] "GET /login HTTP/1.1" 200 1078 +192.168.1.111 - - [27/Jul/2026:15:56:41 +0000] "GET /login HTTP/1.1" 200 1558 +192.168.1.212 - - [27/Jul/2026:15:34:56 +0000] "GET /index.html HTTP/1.1" 200 4258 +192.168.1.17 - - [27/Jul/2026:16:06:43 +0000] "GET /about HTTP/1.1" 404 3140 +203.0.113.45 - - [27/Jul/2026:16:30:08 +0000] "GET /login?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 500 512 +192.168.1.249 - - [27/Jul/2026:16:26:45 +0000] "GET /about HTTP/1.1" 200 368 +192.168.1.171 - - [27/Jul/2026:16:13:17 +0000] "GET /login HTTP/1.1" 200 3660 +192.168.1.187 - - [27/Jul/2026:15:40:48 +0000] "GET /products HTTP/1.1" 200 340 +192.168.1.102 - - [27/Jul/2026:15:43:53 +0000] "GET /about HTTP/1.1" 404 238 +192.168.1.206 - - [27/Jul/2026:15:47:28 +0000] "GET /about HTTP/1.1" 304 3511 +45.155.205.7 - - [27/Jul/2026:16:29:11 +0000] "GET /wp-admin/916.php HTTP/1.1" 404 200 +192.168.1.172 - - [27/Jul/2026:16:09:25 +0000] "GET /products HTTP/1.1" 404 4053 +192.168.1.118 - - [27/Jul/2026:15:33:27 +0000] "GET /index.html HTTP/1.1" 200 2108 +192.168.1.117 - - [27/Jul/2026:15:34:27 +0000] "GET /api/users HTTP/1.1" 404 2850 +192.168.1.225 - - [27/Jul/2026:15:58:35 +0000] "GET /index.html HTTP/1.1" 304 2405 +192.168.1.152 - - [27/Jul/2026:15:50:33 +0000] "GET /products HTTP/1.1" 200 3407 +192.168.1.41 - - [27/Jul/2026:15:35:35 +0000] "GET /login HTTP/1.1" 200 449 +192.168.1.110 - - [27/Jul/2026:16:26:25 +0000] "GET /about HTTP/1.1" 404 3710 +45.155.205.7 - - [27/Jul/2026:16:25:40 +0000] "GET /wp-admin/202.php HTTP/1.1" 404 200 +198.51.100.23 - - [27/Jul/2026:16:30:42 +0000] "GET /view?page=..%2f..%2f..%2fetc%2fpasswd HTTP/1.1" 403 300 +192.168.1.178 - - [27/Jul/2026:16:15:04 +0000] "GET /products HTTP/1.1" 200 600 +192.168.1.72 - - [27/Jul/2026:16:07:21 +0000] "GET / HTTP/1.1" 200 3809 +203.0.113.45 - - [27/Jul/2026:16:30:18 +0000] "GET /search?q=SELECT * FROM accounts HTTP/1.1" 500 512 +192.168.1.77 - - [27/Jul/2026:16:17:12 +0000] "GET /index.html HTTP/1.1" 200 3067 +192.168.1.12 - - [27/Jul/2026:16:29:00 +0000] "GET /index.html HTTP/1.1" 200 3854 +192.168.1.141 - - [27/Jul/2026:16:29:42 +0000] "GET /index.html HTTP/1.1" 404 463 +192.168.1.57 - - [27/Jul/2026:15:38:44 +0000] "GET / HTTP/1.1" 200 4651 +192.168.1.136 - - [27/Jul/2026:15:33:35 +0000] "GET /api/users HTTP/1.1" 200 4432 +192.168.1.37 - - [27/Jul/2026:16:15:19 +0000] "GET /index.html HTTP/1.1" 200 4847 +45.155.205.7 - - [27/Jul/2026:16:31:15 +0000] "GET /wp-admin/718.php HTTP/1.1" 404 200 +192.168.1.223 - - [27/Jul/2026:16:28:45 +0000] "GET /api/users HTTP/1.1" 200 4447 +192.168.1.89 - - [27/Jul/2026:16:09:42 +0000] "GET /index.html HTTP/1.1" 200 675 +192.168.1.31 - - [27/Jul/2026:16:27:00 +0000] "GET /products HTTP/1.1" 200 4619 +192.168.1.102 - - [27/Jul/2026:16:27:01 +0000] "GET / HTTP/1.1" 200 4059 +192.168.1.220 - - [27/Jul/2026:16:14:34 +0000] "GET /products HTTP/1.1" 304 2795 +192.168.1.242 - - [27/Jul/2026:15:46:49 +0000] "GET /products HTTP/1.1" 200 1089 +192.168.1.207 - - [27/Jul/2026:15:59:57 +0000] "GET /api/users HTTP/1.1" 304 2734 +192.168.1.19 - - [27/Jul/2026:16:03:18 +0000] "GET /index.html HTTP/1.1" 200 2757 +192.168.1.15 - - [27/Jul/2026:15:52:29 +0000] "GET /about HTTP/1.1" 200 528 +192.168.1.189 - - [27/Jul/2026:15:37:30 +0000] "GET /index.html HTTP/1.1" 200 4266 +192.168.1.76 - - [27/Jul/2026:16:31:22 +0000] "GET /index.html HTTP/1.1" 304 3697 +192.168.1.150 - - [27/Jul/2026:15:50:13 +0000] "GET /index.html HTTP/1.1" 200 943 +192.168.1.103 - - [27/Jul/2026:15:49:52 +0000] "GET /products HTTP/1.1" 200 2901 +192.168.1.47 - - [27/Jul/2026:16:08:54 +0000] "GET /products HTTP/1.1" 200 3821 +192.168.1.165 - - [27/Jul/2026:15:42:49 +0000] "GET /products HTTP/1.1" 200 2975 +192.168.1.12 - - [27/Jul/2026:15:51:55 +0000] "GET /about HTTP/1.1" 200 1495 +192.168.1.78 - - [27/Jul/2026:15:46:47 +0000] "GET /api/users HTTP/1.1" 404 1264 +45.155.205.7 - - [27/Jul/2026:16:23:44 +0000] "GET /wp-admin/401.php HTTP/1.1" 404 200 +45.155.205.7 - - [27/Jul/2026:16:25:21 +0000] "GET /wp-admin/348.php HTTP/1.1" 404 200 +192.168.1.166 - - [27/Jul/2026:16:26:21 +0000] "GET /index.html HTTP/1.1" 404 2005 +192.168.1.151 - - [27/Jul/2026:16:18:57 +0000] "GET /about HTTP/1.1" 200 2291 +192.168.1.197 - - [27/Jul/2026:15:57:05 +0000] "GET /api/users HTTP/1.1" 404 3742 +198.51.100.23 - - [27/Jul/2026:16:32:33 +0000] "GET /view?page=..%2f..%2f..%2fetc%2fpasswd HTTP/1.1" 403 300 +192.168.1.52 - - [27/Jul/2026:15:33:21 +0000] "GET /api/users HTTP/1.1" 200 1970 +192.168.1.131 - - [27/Jul/2026:16:24:41 +0000] "GET / HTTP/1.1" 200 2387 +192.168.1.71 - - [27/Jul/2026:16:28:58 +0000] "GET /about HTTP/1.1" 304 1029 +192.168.1.181 - - [27/Jul/2026:16:25:06 +0000] "GET /api/users HTTP/1.1" 200 2641 +192.168.1.181 - - [27/Jul/2026:16:19:52 +0000] "GET /about HTTP/1.1" 404 2959 +192.168.1.4 - - [27/Jul/2026:15:50:47 +0000] "GET /login HTTP/1.1" 200 234 +192.168.1.235 - - [27/Jul/2026:15:38:32 +0000] "GET / HTTP/1.1" 200 1932 +192.168.1.117 - - [27/Jul/2026:16:05:46 +0000] "GET / HTTP/1.1" 200 354 +192.168.1.202 - - [27/Jul/2026:16:18:38 +0000] "GET /login HTTP/1.1" 200 3548 +192.168.1.139 - - [27/Jul/2026:15:54:50 +0000] "GET /products HTTP/1.1" 200 954 +192.168.1.70 - - [27/Jul/2026:15:37:09 +0000] "GET / HTTP/1.1" 200 1801 +192.168.1.201 - - [27/Jul/2026:15:41:59 +0000] "GET /about HTTP/1.1" 200 2234 +192.168.1.198 - - [27/Jul/2026:15:35:45 +0000] "GET / HTTP/1.1" 200 290 +192.168.1.175 - - [27/Jul/2026:15:48:30 +0000] "GET /about HTTP/1.1" 404 538 +192.168.1.163 - - [27/Jul/2026:16:13:36 +0000] "GET /api/users HTTP/1.1" 404 2355 +192.168.1.133 - - [27/Jul/2026:16:09:59 +0000] "GET /api/users HTTP/1.1" 200 2211 +192.168.1.79 - - [27/Jul/2026:16:00:39 +0000] "GET /about HTTP/1.1" 200 3603 +45.155.205.7 - - [27/Jul/2026:16:27:26 +0000] "GET /wp-admin/679.php HTTP/1.1" 404 200 +45.155.205.7 - - [27/Jul/2026:16:32:07 +0000] "GET /wp-admin/130.php HTTP/1.1" 404 200 +192.168.1.105 - - [27/Jul/2026:15:49:36 +0000] "GET /login HTTP/1.1" 200 1052 +192.168.1.84 - - [27/Jul/2026:15:38:10 +0000] "GET / HTTP/1.1" 404 3798 +192.168.1.42 - - [27/Jul/2026:16:23:14 +0000] "GET /api/users HTTP/1.1" 200 3742 +192.168.1.138 - - [27/Jul/2026:16:29:30 +0000] "GET /login HTTP/1.1" 200 2907 +192.168.1.82 - - [27/Jul/2026:16:10:37 +0000] "GET /about HTTP/1.1" 404 4025 +192.168.1.188 - - [27/Jul/2026:16:32:12 +0000] "GET /index.html HTTP/1.1" 200 452 +192.168.1.216 - - [27/Jul/2026:15:37:12 +0000] "GET /index.html HTTP/1.1" 200 3957 +192.168.1.230 - - [27/Jul/2026:15:39:16 +0000] "GET /about HTTP/1.1" 200 1616 +45.155.205.7 - - [27/Jul/2026:16:26:22 +0000] "GET /wp-admin/612.php HTTP/1.1" 404 200 +192.168.1.210 - - [27/Jul/2026:16:02:26 +0000] "GET / HTTP/1.1" 200 4939 +192.168.1.158 - - [27/Jul/2026:15:45:16 +0000] "GET /about HTTP/1.1" 200 3150 +45.155.205.7 - - [27/Jul/2026:16:32:08 +0000] "GET /wp-admin/332.php HTTP/1.1" 404 200 +192.168.1.191 - - [27/Jul/2026:15:35:02 +0000] "GET /api/users HTTP/1.1" 304 4968 +192.168.1.105 - - [27/Jul/2026:16:10:11 +0000] "GET /about HTTP/1.1" 304 1988 +192.168.1.212 - - [27/Jul/2026:16:04:10 +0000] "GET /login HTTP/1.1" 304 1650 +192.168.1.25 - - [27/Jul/2026:16:20:20 +0000] "GET /index.html HTTP/1.1" 200 1767 +192.168.1.11 - - [27/Jul/2026:15:56:50 +0000] "GET /about HTTP/1.1" 304 1536 +192.168.1.247 - - [27/Jul/2026:16:22:42 +0000] "GET /index.html HTTP/1.1" 200 3316 +192.168.1.73 - - [27/Jul/2026:16:04:11 +0000] "GET /index.html HTTP/1.1" 200 4471 +192.168.1.123 - - [27/Jul/2026:16:30:40 +0000] "GET /index.html HTTP/1.1" 200 2787 +192.168.1.129 - - [27/Jul/2026:16:23:20 +0000] "GET /about HTTP/1.1" 304 3934 +192.168.1.119 - - [27/Jul/2026:16:13:09 +0000] "GET /index.html HTTP/1.1" 200 3198 +192.168.1.131 - - [27/Jul/2026:16:29:45 +0000] "GET /api/users HTTP/1.1" 200 704 +192.168.1.46 - - [27/Jul/2026:15:49:40 +0000] "GET /index.html HTTP/1.1" 200 3287 +192.168.1.134 - - [27/Jul/2026:16:19:27 +0000] "GET /products HTTP/1.1" 404 604 +192.168.1.153 - - [27/Jul/2026:15:57:55 +0000] "GET /about HTTP/1.1" 200 315 +192.168.1.170 - - [27/Jul/2026:15:42:39 +0000] "GET /api/users HTTP/1.1" 200 2979 +192.168.1.71 - - [27/Jul/2026:16:24:07 +0000] "GET / HTTP/1.1" 304 2928 +192.168.1.59 - - [27/Jul/2026:15:46:45 +0000] "GET / HTTP/1.1" 200 4167 +192.168.1.109 - - [27/Jul/2026:16:18:31 +0000] "GET /api/users HTTP/1.1" 304 2830 +192.168.1.204 - - [27/Jul/2026:15:40:16 +0000] "GET / HTTP/1.1" 200 3575 +192.168.1.93 - - [27/Jul/2026:16:18:45 +0000] "GET /index.html HTTP/1.1" 200 1464 +192.168.1.219 - - [27/Jul/2026:15:38:25 +0000] "GET /login HTTP/1.1" 304 3105 +192.168.1.130 - - [27/Jul/2026:15:36:39 +0000] "GET / HTTP/1.1" 404 3810 +192.168.1.238 - - [27/Jul/2026:15:38:16 +0000] "GET /api/users HTTP/1.1" 200 392 +192.168.1.228 - - [27/Jul/2026:16:26:13 +0000] "GET /api/users HTTP/1.1" 200 300 +192.168.1.29 - - [27/Jul/2026:16:15:29 +0000] "GET /api/users HTTP/1.1" 200 1568 +192.168.1.76 - - [27/Jul/2026:15:33:10 +0000] "GET /about HTTP/1.1" 404 2582 +192.168.1.125 - - [27/Jul/2026:15:49:37 +0000] "GET /login HTTP/1.1" 304 2990 +45.155.205.7 - - [27/Jul/2026:16:23:31 +0000] "GET /wp-admin/478.php HTTP/1.1" 404 200 +192.168.1.10 - - [27/Jul/2026:15:51:07 +0000] "GET /index.html HTTP/1.1" 200 611 +203.0.113.45 - - [27/Jul/2026:16:27:08 +0000] "GET /products?id=1 OR 1=1 HTTP/1.1" 500 512 +192.168.1.102 - - [27/Jul/2026:16:16:45 +0000] "GET / HTTP/1.1" 404 2937 +192.168.1.112 - - [27/Jul/2026:16:21:47 +0000] "GET /products HTTP/1.1" 200 677 +192.168.1.249 - - [27/Jul/2026:15:51:48 +0000] "GET /api/users HTTP/1.1" 200 4230 +192.168.1.47 - - [27/Jul/2026:15:48:40 +0000] "GET / HTTP/1.1" 200 2316 +192.168.1.57 - - [27/Jul/2026:16:07:48 +0000] "GET /login HTTP/1.1" 404 3876 +192.168.1.33 - - [27/Jul/2026:16:08:58 +0000] "GET /login HTTP/1.1" 200 4859 +192.168.1.102 - - [27/Jul/2026:16:14:16 +0000] "GET /api/users HTTP/1.1" 304 1831 +192.168.1.194 - - [27/Jul/2026:15:48:42 +0000] "GET /index.html HTTP/1.1" 200 3063 +192.168.1.119 - - [27/Jul/2026:15:46:34 +0000] "GET /about HTTP/1.1" 304 3915 +192.168.1.168 - - [27/Jul/2026:15:48:47 +0000] "GET /api/users HTTP/1.1" 200 1402 +192.168.1.240 - - [27/Jul/2026:15:53:51 +0000] "GET /api/users HTTP/1.1" 404 1454 +192.168.1.107 - - [27/Jul/2026:16:03:57 +0000] "GET /login HTTP/1.1" 200 4713 +192.168.1.229 - - [27/Jul/2026:15:47:47 +0000] "GET /login HTTP/1.1" 200 1255 +192.168.1.133 - - [27/Jul/2026:16:00:45 +0000] "GET /api/users HTTP/1.1" 200 2459 +45.155.205.7 - - [27/Jul/2026:16:29:22 +0000] "GET /wp-admin/868.php HTTP/1.1" 404 200 +192.168.1.14 - - [27/Jul/2026:16:04:57 +0000] "GET /api/users HTTP/1.1" 200 1857 +192.168.1.194 - - [27/Jul/2026:15:45:24 +0000] "GET /api/users HTTP/1.1" 304 2551 +45.155.205.7 - - [27/Jul/2026:16:31:57 +0000] "GET /wp-admin/176.php HTTP/1.1" 404 200 +192.168.1.127 - - [27/Jul/2026:16:26:52 +0000] "GET /login HTTP/1.1" 404 1661 +192.168.1.48 - - [27/Jul/2026:16:01:43 +0000] "GET /products HTTP/1.1" 200 1821 +192.168.1.185 - - [27/Jul/2026:15:37:09 +0000] "GET /products HTTP/1.1" 200 3352 +192.168.1.100 - - [27/Jul/2026:15:54:11 +0000] "GET / HTTP/1.1" 200 829 +192.168.1.43 - - [27/Jul/2026:15:53:27 +0000] "GET /about HTTP/1.1" 200 3668 +192.168.1.2 - - [27/Jul/2026:16:21:37 +0000] "GET /index.html HTTP/1.1" 304 4685 +192.168.1.10 - - [27/Jul/2026:16:24:20 +0000] "GET /api/users HTTP/1.1" 200 2700 +192.168.1.4 - - [27/Jul/2026:16:19:04 +0000] "GET / HTTP/1.1" 200 377 +192.168.1.134 - - [27/Jul/2026:16:10:17 +0000] "GET / HTTP/1.1" 404 3471 +192.168.1.53 - - [27/Jul/2026:16:29:53 +0000] "GET /api/users HTTP/1.1" 304 1184 +192.168.1.33 - - [27/Jul/2026:15:33:58 +0000] "GET /api/users HTTP/1.1" 304 1380 +192.168.1.235 - - [27/Jul/2026:16:09:09 +0000] "GET / HTTP/1.1" 200 2162 +192.168.1.51 - - [27/Jul/2026:15:43:22 +0000] "GET / HTTP/1.1" 404 1806 +45.155.205.7 - - [27/Jul/2026:16:31:29 +0000] "GET /wp-admin/189.php HTTP/1.1" 404 200 +192.168.1.221 - - [27/Jul/2026:16:03:03 +0000] "GET / HTTP/1.1" 404 4055 +45.155.205.7 - - [27/Jul/2026:16:23:30 +0000] "GET /wp-admin/335.php HTTP/1.1" 404 200 +192.168.1.53 - - [27/Jul/2026:15:45:41 +0000] "GET /index.html HTTP/1.1" 200 4514 +192.168.1.101 - - [27/Jul/2026:15:34:53 +0000] "GET /api/users HTTP/1.1" 404 3070 +198.51.100.23 - - [27/Jul/2026:16:30:48 +0000] "GET /download?file=../../../../etc/passwd HTTP/1.1" 403 300 +192.168.1.244 - - [27/Jul/2026:16:24:50 +0000] "GET /index.html HTTP/1.1" 200 2261 +192.168.1.180 - - [27/Jul/2026:16:32:35 +0000] "GET /index.html HTTP/1.1" 200 2223 +192.168.1.56 - - [27/Jul/2026:15:39:52 +0000] "GET /index.html HTTP/1.1" 200 4911 +45.155.205.7 - - [27/Jul/2026:16:29:13 +0000] "GET /wp-admin/339.php HTTP/1.1" 404 200 +192.168.1.152 - - [27/Jul/2026:15:44:07 +0000] "GET /login HTTP/1.1" 304 3569 +192.168.1.106 - - [27/Jul/2026:15:50:29 +0000] "GET /index.html HTTP/1.1" 304 3255 +192.168.1.116 - - [27/Jul/2026:16:32:09 +0000] "GET /products HTTP/1.1" 200 2001 +192.168.1.35 - - [27/Jul/2026:16:05:42 +0000] "GET /login HTTP/1.1" 404 1478 +192.168.1.165 - - [27/Jul/2026:16:20:04 +0000] "GET /index.html HTTP/1.1" 200 3331 +45.155.205.7 - - [27/Jul/2026:16:29:47 +0000] "GET /wp-admin/990.php HTTP/1.1" 404 200 +192.168.1.134 - - [27/Jul/2026:16:13:47 +0000] "GET /api/users HTTP/1.1" 200 3898 +192.168.1.200 - - [27/Jul/2026:15:52:33 +0000] "GET / HTTP/1.1" 304 587 +192.168.1.177 - - [27/Jul/2026:15:50:47 +0000] "GET /about HTTP/1.1" 404 2572 +192.168.1.120 - - [27/Jul/2026:15:55:34 +0000] "GET /api/users HTTP/1.1" 200 3979 +203.0.113.45 - - [27/Jul/2026:16:26:12 +0000] "GET /search?q=SELECT * FROM accounts HTTP/1.1" 500 512 +192.168.1.12 - - [27/Jul/2026:15:47:33 +0000] "GET /index.html HTTP/1.1" 404 3465 +192.168.1.26 - - [27/Jul/2026:16:23:15 +0000] "GET / HTTP/1.1" 200 3811 +192.168.1.32 - - [27/Jul/2026:15:52:18 +0000] "GET / HTTP/1.1" 304 894 +192.168.1.246 - - [27/Jul/2026:16:22:32 +0000] "GET /api/users HTTP/1.1" 404 2709 +192.168.1.147 - - [27/Jul/2026:15:37:43 +0000] "GET /products HTTP/1.1" 200 4652 +192.168.1.211 - - [27/Jul/2026:16:11:50 +0000] "GET /about HTTP/1.1" 404 4623 +45.155.205.7 - - [27/Jul/2026:16:23:55 +0000] "GET /wp-admin/253.php HTTP/1.1" 404 200 +192.168.1.56 - - [27/Jul/2026:16:19:46 +0000] "GET / HTTP/1.1" 200 2965 +192.168.1.38 - - [27/Jul/2026:16:29:34 +0000] "GET /products HTTP/1.1" 200 2947 +192.168.1.168 - - [27/Jul/2026:16:25:07 +0000] "GET /login HTTP/1.1" 200 3966 +192.168.1.17 - - [27/Jul/2026:16:15:10 +0000] "GET /login HTTP/1.1" 200 4692 +192.168.1.84 - - [27/Jul/2026:16:29:17 +0000] "GET /about HTTP/1.1" 304 4771 +192.168.1.228 - - [27/Jul/2026:15:43:57 +0000] "GET /index.html HTTP/1.1" 404 862 +45.155.205.7 - - [27/Jul/2026:16:29:47 +0000] "GET /wp-admin/557.php HTTP/1.1" 404 200 +192.168.1.202 - - [27/Jul/2026:15:36:05 +0000] "GET /login HTTP/1.1" 200 4410 +192.168.1.244 - - [27/Jul/2026:16:23:27 +0000] "GET /login HTTP/1.1" 304 4208 +192.168.1.103 - - [27/Jul/2026:16:25:05 +0000] "GET /api/users HTTP/1.1" 404 3744 +192.168.1.48 - - [27/Jul/2026:15:48:03 +0000] "GET /products HTTP/1.1" 304 3074 +192.168.1.155 - - [27/Jul/2026:16:05:52 +0000] "GET /login HTTP/1.1" 200 1548 +192.168.1.151 - - [27/Jul/2026:16:27:47 +0000] "GET / HTTP/1.1" 404 3321 +192.168.1.38 - - [27/Jul/2026:16:28:15 +0000] "GET /login HTTP/1.1" 404 1797 +192.168.1.224 - - [27/Jul/2026:16:15:08 +0000] "GET /login HTTP/1.1" 200 3260 +192.168.1.7 - - [27/Jul/2026:15:54:23 +0000] "GET /login HTTP/1.1" 200 4584 +192.168.1.196 - - [27/Jul/2026:16:16:50 +0000] "GET /index.html HTTP/1.1" 200 3997 +192.168.1.65 - - [27/Jul/2026:16:28:44 +0000] "GET /about HTTP/1.1" 304 1110 +192.168.1.234 - - [27/Jul/2026:16:15:07 +0000] "GET / HTTP/1.1" 200 4756 +192.168.1.199 - - [27/Jul/2026:15:45:52 +0000] "GET / HTTP/1.1" 304 3470 +192.168.1.140 - - [27/Jul/2026:15:43:09 +0000] "GET /index.html HTTP/1.1" 200 4476 +192.168.1.20 - - [27/Jul/2026:15:38:34 +0000] "GET /products HTTP/1.1" 200 1686 +192.168.1.43 - - [27/Jul/2026:15:54:07 +0000] "GET /index.html HTTP/1.1" 304 4486 +192.168.1.221 - - [27/Jul/2026:16:05:07 +0000] "GET /login HTTP/1.1" 200 817 +192.168.1.105 - - [27/Jul/2026:16:10:37 +0000] "GET /api/users HTTP/1.1" 404 3423 +192.168.1.85 - - [27/Jul/2026:15:49:14 +0000] "GET /login HTTP/1.1" 200 3876 +192.168.1.166 - - [27/Jul/2026:16:13:01 +0000] "GET /products HTTP/1.1" 200 2653 +192.168.1.128 - - [27/Jul/2026:15:45:26 +0000] "GET / HTTP/1.1" 200 2750 +192.168.1.88 - - [27/Jul/2026:16:17:18 +0000] "GET /index.html HTTP/1.1" 200 1240 +192.168.1.6 - - [27/Jul/2026:15:37:57 +0000] "GET /api/users HTTP/1.1" 304 1124 +192.168.1.58 - - [27/Jul/2026:15:39:36 +0000] "GET /index.html HTTP/1.1" 200 4119 +192.168.1.201 - - [27/Jul/2026:15:39:09 +0000] "GET /products HTTP/1.1" 200 1308 +192.168.1.175 - - [27/Jul/2026:15:35:07 +0000] "GET /products HTTP/1.1" 200 1344 +192.168.1.196 - - [27/Jul/2026:16:14:56 +0000] "GET /about HTTP/1.1" 200 2202 +192.168.1.218 - - [27/Jul/2026:16:09:58 +0000] "GET /products HTTP/1.1" 200 500 +192.168.1.50 - - [27/Jul/2026:15:57:38 +0000] "GET /products HTTP/1.1" 200 4677 +192.168.1.239 - - [27/Jul/2026:15:40:16 +0000] "GET /products HTTP/1.1" 200 3416 +192.168.1.109 - - [27/Jul/2026:16:27:41 +0000] "GET /about HTTP/1.1" 404 391 +192.168.1.144 - - [27/Jul/2026:16:07:44 +0000] "GET /index.html HTTP/1.1" 200 4741 +192.168.1.207 - - [27/Jul/2026:16:10:47 +0000] "GET /api/users HTTP/1.1" 304 2454 diff --git a/q4-siem-log-analysis/alerts.json b/q4-siem-log-analysis/alerts.json new file mode 100644 index 0000000..61f97fc --- /dev/null +++ b/q4-siem-log-analysis/alerts.json @@ -0,0 +1,98 @@ +{ + "generated_at": "2026-07-27T16:33:08.411673", + "stats": { + "total_alerts": 9, + "by_source": { + "web": 7, + "auth": 1, + "firewall": 1 + }, + "by_severity": { + "high": 8, + "medium": 1 + }, + "unique_suspicious_ips": 3 + }, + "alerts": [ + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/download?file=../../../../etc/passwd", + "severity": "high" + }, + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/download?file=../../../../etc/passwd", + "severity": "high" + }, + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/view?page=..%2f..%2f..%2fetc%2fpasswd", + "severity": "high" + }, + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/view?page=..%2f..%2f..%2fetc%2fpasswd", + "severity": "high" + }, + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/view?page=..%2f..%2f..%2fetc%2fpasswd", + "severity": "high" + }, + { + "source": "web", + "type": "Directory Traversal", + "ip": "198.51.100.23", + "detail": "/download?file=../../../../etc/passwd", + "severity": "high" + }, + { + "source": "auth", + "type": "Brute Force (SSH)", + "ip": "198.51.100.99", + "detail": "10 محاولة فاشلة", + "severity": "high" + }, + { + "source": "firewall", + "type": "Port Scanning", + "ip": "45.155.205.7", + "detail": "محاولة الاتصال بـ 35 منفذ مختلف", + "severity": "high" + }, + { + "source": "web", + "type": "Scanning/Fuzzing", + "ip": "45.155.205.7", + "detail": "40 طلب 404/403 من نفس المصدر", + "severity": "medium" + } + ], + "suspicious_ips": [ + { + "ip": "198.51.100.23", + "score": 18, + "alert_count": 6 + }, + { + "ip": "45.155.205.7", + "score": 5, + "alert_count": 2 + }, + { + "ip": "198.51.100.99", + "score": 3, + "alert_count": 1 + } + ] +} \ No newline at end of file diff --git a/q4-siem-log-analysis/auth.log b/q4-siem-log-analysis/auth.log new file mode 100644 index 0000000..b566a62 --- /dev/null +++ b/q4-siem-log-analysis/auth.log @@ -0,0 +1,31 @@ +Jul 27 16:31:18 server sshd[9992]: Failed password for root from 198.51.100.99 port 44442 ssh2 +Jul 27 15:51:47 server sshd[1234]: Accepted password for admin from 192.168.1.42 port 55000 ssh2 +Jul 27 16:31:08 server sshd[9990]: Failed password for root from 198.51.100.99 port 44440 ssh2 +Jul 27 16:31:23 server sshd[9993]: Failed password for root from 198.51.100.99 port 44443 ssh2 +Jul 27 16:32:08 server sshd[9999]: Accepted password for root from 198.51.100.99 port 44450 ssh2 +Jul 27 15:50:35 server sshd[1234]: Accepted password for admin from 192.168.1.56 port 55000 ssh2 +Jul 27 15:34:46 server sshd[1234]: Accepted password for admin from 192.168.1.34 port 55000 ssh2 +Jul 27 16:17:58 server sshd[1234]: Accepted password for admin from 192.168.1.17 port 55000 ssh2 +Jul 27 15:42:24 server sshd[1234]: Accepted password for admin from 192.168.1.171 port 55000 ssh2 +Jul 27 16:23:21 server sshd[1234]: Accepted password for admin from 192.168.1.104 port 55000 ssh2 +Jul 27 16:31:13 server sshd[9991]: Failed password for root from 198.51.100.99 port 44441 ssh2 +Jul 27 16:12:07 server sshd[1234]: Accepted password for admin from 192.168.1.27 port 55000 ssh2 +Jul 27 16:31:28 server sshd[9994]: Failed password for root from 198.51.100.99 port 44444 ssh2 +Jul 27 15:47:44 server sshd[1234]: Accepted password for admin from 192.168.1.59 port 55000 ssh2 +Jul 27 15:57:23 server sshd[1234]: Accepted password for admin from 192.168.1.56 port 55000 ssh2 +Jul 27 16:20:48 server sshd[1234]: Accepted password for admin from 192.168.1.6 port 55000 ssh2 +Jul 27 15:38:33 server sshd[1234]: Accepted password for admin from 192.168.1.113 port 55000 ssh2 +Jul 27 16:31:38 server sshd[9996]: Failed password for root from 198.51.100.99 port 44446 ssh2 +Jul 27 16:31:53 server sshd[9999]: Failed password for root from 198.51.100.99 port 44449 ssh2 +Jul 27 16:31:48 server sshd[9998]: Failed password for root from 198.51.100.99 port 44448 ssh2 +Jul 27 15:44:07 server sshd[1234]: Accepted password for admin from 192.168.1.25 port 55000 ssh2 +Jul 27 15:35:32 server sshd[1234]: Accepted password for admin from 192.168.1.157 port 55000 ssh2 +Jul 27 15:39:49 server sshd[1234]: Accepted password for admin from 192.168.1.33 port 55000 ssh2 +Jul 27 15:54:56 server sshd[1234]: Accepted password for admin from 192.168.1.220 port 55000 ssh2 +Jul 27 16:01:40 server sshd[1234]: Accepted password for admin from 192.168.1.2 port 55000 ssh2 +Jul 27 16:19:47 server sshd[1234]: Accepted password for admin from 192.168.1.202 port 55000 ssh2 +Jul 27 16:31:33 server sshd[9995]: Failed password for root from 198.51.100.99 port 44445 ssh2 +Jul 27 16:13:24 server sshd[1234]: Accepted password for admin from 192.168.1.130 port 55000 ssh2 +Jul 27 16:15:23 server sshd[1234]: Accepted password for admin from 192.168.1.17 port 55000 ssh2 +Jul 27 16:32:40 server sshd[1234]: Accepted password for admin from 192.168.1.9 port 55000 ssh2 +Jul 27 16:31:43 server sshd[9997]: Failed password for root from 198.51.100.99 port 44447 ssh2 diff --git a/q4-siem-log-analysis/dashboard.html b/q4-siem-log-analysis/dashboard.html new file mode 100644 index 0000000..ef70d6b --- /dev/null +++ b/q4-siem-log-analysis/dashboard.html @@ -0,0 +1,214 @@ + + + + +SIEM Dashboard | لوحة المراقبة الأمنية + + + + +
+

SIEM / نظام مراقبة الأحداث الأمنية

+
لم يتم التحميل بعد
+
+ +
+ + + يحاول تحميل alerts.json تلقائيًا كل 10 ثوانٍ (يتطلب تشغيل عبر خادم محلي) +
+ +
+
+
+
+

التنبيهات (Alerts)

+
+
+
+

عناوين IP المشبوهة

+
+
+

التنبيهات حسب المصدر

+
+
+
+
+
+ + + + diff --git a/q4-siem-log-analysis/firewall.log b/q4-siem-log-analysis/firewall.log new file mode 100644 index 0000000..ffd59a1 --- /dev/null +++ b/q4-siem-log-analysis/firewall.log @@ -0,0 +1,95 @@ +Jul 27 16:03:12 kernel: IN=eth0 OUT= SRC=192.168.1.167 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:59:26 kernel: IN=eth0 OUT= SRC=192.168.1.29 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:36:52 kernel: IN=eth0 OUT= SRC=192.168.1.230 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:29:12 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1007 ACTION=DROP +Jul 27 15:36:19 kernel: IN=eth0 OUT= SRC=192.168.1.16 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:16:10 kernel: IN=eth0 OUT= SRC=192.168.1.200 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:29:59 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1024 ACTION=DROP +Jul 27 16:06:48 kernel: IN=eth0 OUT= SRC=192.168.1.79 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:37:48 kernel: IN=eth0 OUT= SRC=192.168.1.97 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:18:19 kernel: IN=eth0 OUT= SRC=192.168.1.38 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:27:14 kernel: IN=eth0 OUT= SRC=192.168.1.118 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:48:38 kernel: IN=eth0 OUT= SRC=192.168.1.118 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:32:35 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1031 ACTION=DROP +Jul 27 16:31:12 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1033 ACTION=DROP +Jul 27 15:46:00 kernel: IN=eth0 OUT= SRC=192.168.1.35 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:18:46 kernel: IN=eth0 OUT= SRC=192.168.1.238 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:31:21 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1028 ACTION=DROP +Jul 27 16:25:19 kernel: IN=eth0 OUT= SRC=192.168.1.51 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:03:13 kernel: IN=eth0 OUT= SRC=192.168.1.187 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:30:48 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1003 ACTION=DROP +Jul 27 16:31:08 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1001 ACTION=DROP +Jul 27 15:36:40 kernel: IN=eth0 OUT= SRC=192.168.1.175 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:31:07 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1025 ACTION=DROP +Jul 27 16:29:06 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1023 ACTION=DROP +Jul 27 16:31:00 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1014 ACTION=DROP +Jul 27 16:32:09 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1005 ACTION=DROP +Jul 27 16:27:56 kernel: IN=eth0 OUT= SRC=192.168.1.182 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 15:49:22 kernel: IN=eth0 OUT= SRC=192.168.1.45 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:00:54 kernel: IN=eth0 OUT= SRC=192.168.1.250 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:30:42 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1019 ACTION=DROP +Jul 27 16:28:08 kernel: IN=eth0 OUT= SRC=192.168.1.41 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 15:39:55 kernel: IN=eth0 OUT= SRC=192.168.1.172 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:28:15 kernel: IN=eth0 OUT= SRC=192.168.1.193 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:30:10 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1021 ACTION=DROP +Jul 27 15:38:30 kernel: IN=eth0 OUT= SRC=192.168.1.246 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:58:16 kernel: IN=eth0 OUT= SRC=192.168.1.160 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:11:21 kernel: IN=eth0 OUT= SRC=192.168.1.115 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:32:49 kernel: IN=eth0 OUT= SRC=192.168.1.127 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:31:19 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1000 ACTION=DROP +Jul 27 15:48:01 kernel: IN=eth0 OUT= SRC=192.168.1.228 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:30:48 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1027 ACTION=DROP +Jul 27 16:19:52 kernel: IN=eth0 OUT= SRC=192.168.1.178 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:59:49 kernel: IN=eth0 OUT= SRC=192.168.1.154 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:30:57 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1009 ACTION=DROP +Jul 27 16:02:28 kernel: IN=eth0 OUT= SRC=192.168.1.191 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:15:06 kernel: IN=eth0 OUT= SRC=192.168.1.241 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:30:16 kernel: IN=eth0 OUT= SRC=192.168.1.130 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:31:50 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1012 ACTION=DROP +Jul 27 15:45:51 kernel: IN=eth0 OUT= SRC=192.168.1.71 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:48:51 kernel: IN=eth0 OUT= SRC=192.168.1.231 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:32:53 kernel: IN=eth0 OUT= SRC=192.168.1.24 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:31:49 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1020 ACTION=DROP +Jul 27 15:54:16 kernel: IN=eth0 OUT= SRC=192.168.1.227 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:54:06 kernel: IN=eth0 OUT= SRC=192.168.1.105 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:30:04 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1006 ACTION=DROP +Jul 27 16:32:51 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1018 ACTION=DROP +Jul 27 16:30:32 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1013 ACTION=DROP +Jul 27 16:13:59 kernel: IN=eth0 OUT= SRC=192.168.1.187 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:25:14 kernel: IN=eth0 OUT= SRC=192.168.1.135 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:35:05 kernel: IN=eth0 OUT= SRC=192.168.1.145 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 16:31:51 kernel: IN=eth0 OUT= SRC=192.168.1.122 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:03:22 kernel: IN=eth0 OUT= SRC=192.168.1.9 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:27:41 kernel: IN=eth0 OUT= SRC=192.168.1.89 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 15:53:52 kernel: IN=eth0 OUT= SRC=192.168.1.226 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:14:48 kernel: IN=eth0 OUT= SRC=192.168.1.109 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:30:38 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1008 ACTION=DROP +Jul 27 16:32:05 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1030 ACTION=DROP +Jul 27 16:31:55 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1017 ACTION=DROP +Jul 27 16:31:14 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1016 ACTION=DROP +Jul 27 15:52:30 kernel: IN=eth0 OUT= SRC=192.168.1.84 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:47:16 kernel: IN=eth0 OUT= SRC=192.168.1.3 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:31:04 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1029 ACTION=DROP +Jul 27 16:32:53 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1010 ACTION=DROP +Jul 27 16:00:19 kernel: IN=eth0 OUT= SRC=192.168.1.23 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:30:16 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1032 ACTION=DROP +Jul 27 16:20:28 kernel: IN=eth0 OUT= SRC=192.168.1.119 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:30:59 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1004 ACTION=DROP +Jul 27 16:30:15 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1022 ACTION=DROP +Jul 27 16:14:31 kernel: IN=eth0 OUT= SRC=192.168.1.241 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:50:41 kernel: IN=eth0 OUT= SRC=192.168.1.204 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:31:34 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1011 ACTION=DROP +Jul 27 15:47:24 kernel: IN=eth0 OUT= SRC=192.168.1.69 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 15:38:28 kernel: IN=eth0 OUT= SRC=192.168.1.4 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 15:44:58 kernel: IN=eth0 OUT= SRC=192.168.1.63 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:25:51 kernel: IN=eth0 OUT= SRC=192.168.1.106 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:29:04 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1034 ACTION=DROP +Jul 27 15:35:29 kernel: IN=eth0 OUT= SRC=192.168.1.93 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:29:19 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1026 ACTION=DROP +Jul 27 15:42:51 kernel: IN=eth0 OUT= SRC=192.168.1.181 DST=10.0.0.5 PROTO=TCP DPT=443 ACTION=ACCEPT +Jul 27 15:57:22 kernel: IN=eth0 OUT= SRC=192.168.1.245 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:23:44 kernel: IN=eth0 OUT= SRC=192.168.1.101 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 16:29:13 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1015 ACTION=DROP +Jul 27 15:33:35 kernel: IN=eth0 OUT= SRC=192.168.1.221 DST=10.0.0.5 PROTO=TCP DPT=80 ACTION=ACCEPT +Jul 27 15:55:22 kernel: IN=eth0 OUT= SRC=192.168.1.43 DST=10.0.0.5 PROTO=TCP DPT=22 ACTION=ACCEPT +Jul 27 16:31:22 kernel: IN=eth0 OUT= SRC=45.155.205.7 DST=10.0.0.5 PROTO=TCP DPT=1002 ACTION=DROP diff --git a/q4-siem-log-analysis/generate_sample_logs.py b/q4-siem-log-analysis/generate_sample_logs.py new file mode 100644 index 0000000..5f03e72 --- /dev/null +++ b/q4-siem-log-analysis/generate_sample_logs.py @@ -0,0 +1,130 @@ +#!/usr/bin/env python3 +""" +generate_sample_logs.py +------------------------ +يولد سجلات تجريبية واقعية (Web / Auth / Firewall) تحتوي على سلوك طبيعي ++ هجمات مصطنعة، لاختبار محرك التحليل siem_analyzer.py قبل تسليم الامتحان. + +الاستخدام: + python3 generate_sample_logs.py +سينشئ الملفات داخل مجلد logs/: + logs/access.log (Nginx) + logs/auth.log (Linux SSH) + logs/firewall.log (iptables) +""" + +import random +from datetime import datetime, timedelta + +OUT_DIR = "logs" + + +def rand_ip(bad=False): + if bad: + # نفس مجموعة IPs الخبيثة تتكرر لتصبح واضحة الأنماط + return random.choice(["203.0.113.45", "198.51.100.23", "45.155.205.7"]) + return f"192.168.1.{random.randint(2, 250)}" + + +def gen_access_log(out_path, lines=400): + normal_paths = ["/", "/index.html", "/products", "/login", "/api/users", "/about"] + sqli_payloads = [ + "/login?id=1' UNION SELECT username,password FROM users--", + "/products?id=1 OR 1=1", + "/search?q=SELECT * FROM accounts", + ] + traversal_payloads = [ + "/download?file=../../../../etc/passwd", + "/view?page=..%2f..%2f..%2fetc%2fpasswd", + ] + now = datetime.now() + rows = [] + for i in range(lines): + ts = now - timedelta(seconds=random.randint(0, 3600)) + ip = rand_ip() + req_path = random.choice(normal_paths) + status = random.choice([200, 200, 200, 304, 404]) + rows.append(f'{ip} - - [{ts.strftime("%d/%b/%Y:%H:%M:%S +0000")}] ' + f'"GET {req_path} HTTP/1.1" {status} {random.randint(200,5000)}') + + # هجوم SQL Injection من IP واحد + attacker = "203.0.113.45" + for payload in sqli_payloads * 3: + ts = now - timedelta(seconds=random.randint(0, 600)) + rows.append(f'{attacker} - - [{ts.strftime("%d/%b/%Y:%H:%M:%S +0000")}] ' + f'"GET {payload} HTTP/1.1" 500 512') + + # هجوم Directory Traversal + attacker2 = "198.51.100.23" + for payload in traversal_payloads * 3: + ts = now - timedelta(seconds=random.randint(0, 600)) + rows.append(f'{attacker2} - - [{ts.strftime("%d/%b/%Y:%H:%M:%S +0000")}] ' + f'"GET {payload} HTTP/1.1" 403 300') + + # هجوم Scanning/Fuzzing: نفس IP يولد عشرات 404 + scanner = "45.155.205.7" + for _ in range(40): + ts = now - timedelta(seconds=random.randint(0, 600)) + rows.append(f'{scanner} - - [{ts.strftime("%d/%b/%Y:%H:%M:%S +0000")}] ' + f'"GET /wp-admin/{random.randint(1,999)}.php HTTP/1.1" 404 200') + + random.shuffle(rows) + with open(out_path, "w") as f: + f.write("\n".join(rows) + "\n") + + +def gen_auth_log(out_path): + now = datetime.now() + rows = [] + # محاولات دخول عادية ناجحة + for _ in range(20): + ts = now - timedelta(seconds=random.randint(0, 3600)) + ip = rand_ip() + rows.append(f'{ts.strftime("%b %d %H:%M:%S")} server sshd[1234]: ' + f'Accepted password for admin from {ip} port 55000 ssh2') + + # هجوم Brute Force: نفس IP، فشل متكرر خلال دقيقة ثم نجاح + attacker = "198.51.100.99" + base = now - timedelta(minutes=2) + for i in range(10): + ts = base + timedelta(seconds=i * 5) + rows.append(f'{ts.strftime("%b %d %H:%M:%S")} server sshd[999{i}]: ' + f'Failed password for root from {attacker} port 4444{i} ssh2') + rows.append(f'{(base + timedelta(seconds=60)).strftime("%b %d %H:%M:%S")} server sshd[9999]: ' + f'Accepted password for root from {attacker} port 44450 ssh2') + + random.shuffle(rows) + with open(out_path, "w") as f: + f.write("\n".join(rows) + "\n") + + +def gen_firewall_log(out_path): + now = datetime.now() + rows = [] + # حركة طبيعية مسموحة + for _ in range(60): + ts = now - timedelta(seconds=random.randint(0, 3600)) + ip = rand_ip() + port = random.choice([80, 443, 22]) + rows.append(f'{ts.strftime("%b %d %H:%M:%S")} kernel: IN=eth0 OUT= ' + f'SRC={ip} DST=10.0.0.5 PROTO=TCP DPT={port} ACTION=ACCEPT') + + # هجوم Port Scan: IP واحد يحاول عشرات المنافذ المغلقة + scanner = "45.155.205.7" + for port in range(1000, 1035): + ts = now - timedelta(seconds=random.randint(0, 300)) + rows.append(f'{ts.strftime("%b %d %H:%M:%S")} kernel: IN=eth0 OUT= ' + f'SRC={scanner} DST=10.0.0.5 PROTO=TCP DPT={port} ACTION=DROP') + + random.shuffle(rows) + with open(out_path, "w") as f: + f.write("\n".join(rows) + "\n") + + +if __name__ == "__main__": + import os + os.makedirs(OUT_DIR, exist_ok=True) + gen_access_log(f"{OUT_DIR}/access.log") + gen_auth_log(f"{OUT_DIR}/auth.log") + gen_firewall_log(f"{OUT_DIR}/firewall.log") + print("تم إنشاء سجلات تجريبية داخل مجلد logs/") diff --git a/q4-siem-log-analysis/siem_analyzer.py b/q4-siem-log-analysis/siem_analyzer.py new file mode 100644 index 0000000..894c44e --- /dev/null +++ b/q4-siem-log-analysis/siem_analyzer.py @@ -0,0 +1,218 @@ +#!/usr/bin/env python3 +""" +siem_analyzer.py +----------------- +نظام SIEM مبسط: يجمع السجلات من 3 مصادر (Web Server / Auth-OS / Firewall)، +يحللها لاكتشاف أنماط مشبوهة، ويحفظ النتائج في alerts.json ليقرأها الـ Dashboard. + +الاستخدام: + python3 siem_analyzer.py --once # تشغيل مرة واحدة + python3 siem_analyzer.py --watch 30 # تشغيل دوري كل 30 ثانية (مثل خدمة حقيقية) + +يمكن تعديل مسارات ومحددات (thresholds) الكشف في قسم CONFIG أدناه. +""" + +import re +import json +import argparse +import time +from collections import defaultdict, Counter +from datetime import datetime + +# ================== CONFIG ================== +CONFIG = { + "web_log_path": "logs/access.log", + "auth_log_path": "logs/auth.log", + "firewall_log_path": "logs/firewall.log", + "output_path": "output/alerts.json", + "thresholds": { + "web_404_403_count": 15, # عدد 404/403 من نفس IP يعتبر Scanning + "brute_force_fails": 5, # عدد محاولات فاشلة من نفس IP قبل التنبيه + "port_scan_ports": 15, # عدد منافذ مختلفة محظورة من نفس IP + }, +} + +SQLI_PATTERN = re.compile( + r"(\bunion\b.*\bselect\b|\bselect\b.*\bfrom\b|\bor\b\s+1=1|--\s*$|'.*or.*'.*=.*')", + re.IGNORECASE, +) +TRAVERSAL_PATTERN = re.compile(r"(\.\./|%2e%2e%2f|\.\.%2f)", re.IGNORECASE) +WEB_LOG_LINE = re.compile( + r'(?P\d{1,3}(?:\.\d{1,3}){3}).*\[(?P