A couple of years ago, I got bored and decided to throw together a crude report only web application firewall which basically logged away every suspicious request it detected. I also threw together a nice little graph so I could chart it all out
It's not great for actual security, as WAFs are generally terrible at anything related to security, but it's nice to see what the bots are up-to and to get some debug data from the occasional misbehaving browser or crawler.
Back in the day of 2018, I would get the occasional bot blasting me with 1K requests per second looking for vulnerabilities and not even bothering to conceal it's identity (lol), but it seems they're a bit more subtle now.
Have you ever been curious about what suspicious or malicious activity has been hitting your site? How do you track it? Raw logs? WAF?
It's not great for actual security, as WAFs are generally terrible at anything related to security, but it's nice to see what the bots are up-to and to get some debug data from the occasional misbehaving browser or crawler.
Back in the day of 2018, I would get the occasional bot blasting me with 1K requests per second looking for vulnerabilities and not even bothering to conceal it's identity (lol), but it seems they're a bit more subtle now.
Have you ever been curious about what suspicious or malicious activity has been hitting your site? How do you track it? Raw logs? WAF?







