Weblog Attack Analyzer

Paste web-server access logs and triage likely attack traffic: SQL injection, XSS, path traversal, file inclusion, RCE payloads, scanner user agents, sensitive-path probes, and noisy source IPs. Runs locally in your browser.

Try:
Analysis

What this tool does

Paste Apache, Nginx, or IIS access logs and this tool highlights requests that look like web-application attack traffic. It parses each request, percent-decodes the target once and twice, matches a curated set of signatures, and then rolls findings up by source IP so you can see both individual payloads and noisy offenders.

It flags these classes:

The report also calls out source IPs with high request volume, many 404s (enumeration), or repeated 401/403s (brute-force style behaviour). Use the Blocklist output when you just want one suspicious IP per line.

Worked example

Paste this sample with Output as: Report:

203.0.113.5 - - [11/Mar/2024:09:14:02 +0000] "GET /products.php?id=1%27+UNION+SELECT+null,version()--+- HTTP/1.1" 200 512 "-" "sqlmap/1.7"
203.0.113.5 - - [11/Mar/2024:09:14:05 +0000] "GET /admin/../../etc/passwd HTTP/1.1" 404 153 "-" "sqlmap/1.7"
198.51.100.22 - - [11/Mar/2024:09:14:20 +0000] "GET /search?q=%3Cscript%3Ealert(1)%3C/script%3E HTTP/1.1" 200 980 "-" "Mozilla/5.0"

The output starts with a compact caption such as:

Weblog attack analysis · combined · 3 requests · 3 flagged · 2 source IPs

Then it lists categories by severity, ranks the top source IPs, and shows each finding with the line number, source IP, request target, status code, and matched signature names.

Limits and edge cases

FAQ

How is this different from the Log Analyzer tool?

Log Analyzer summarizes general log health: severity counts, top errors, time span, and volume. Weblog Attack Analyzer is security-focused: it looks specifically at access-log request targets, status codes, user agents, and source IP behaviour to flag attack attempts and scanning.

Does it upload my logs?

No. The standalone page runs the WebAssembly analyzer in your browser. Chat and CLI runs are local to the gizza runtime as well; there is no registry lookup, enrichment service, or remote scoring API.

Will this catch every attack?

No. It uses deterministic signatures and simple per-IP thresholds. It catches common probes and noisy scans well, but a targeted attacker can evade signatures or blend into normal volume. Treat the output as a prioritized review queue, then confirm with application logs, WAF events, and server context.

Why are percent-decoded matches important?

Attack payloads in URLs are often encoded, sometimes twice. For example %3Cscript%3E is <script> and %252e%252e%252f becomes ../ after two decode passes. The tool checks raw, once-decoded, and twice-decoded targets by default so those probes are not missed.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool weblog-attack-analyzer '203.0.113.5 - - [11/Mar/2024:09:14:02 +0000] "GET /products.php?id=1%27+UNION+SELECT+null,version()--+- HTTP/1.1" 200 512 "-" "sqlmap/1.7"'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/weblog-attack-analyzer/?logs=203.0.113.5%20-%20-%20%5B11%2FMar%2F2024%3A09%3A14%3A02%20%2B0000%5D%20%22GET%20%2Fproducts.php%3Fid%3D1%2527%2BUNION%2BSELECT%2Bnull%2Cversion%28%29--%2B-%20HTTP%2F1.1%22%20200%20512%20%22-%22%20%22sqlmap%2F1.7%22&category=all&min_severity=all&output=report&offender_threshold=20&error_threshold=5&decode=true&limit=500

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.