Loghound parses hostile input by definition: log lines carry paths, User-Agents and referrers chosen by strangers, and the beacon collector is a public write path. This page names the adversaries, what is trusted and what never is, and the limits stated plainly.
Full control of the request path, query string, User-Agent, referrer and every other header — all of which end up as bytes in a log line Loghound parses
Can post to the beacon collector, which is public and unauthenticated by design
Can read world-readable files
Executes as the shared web server user
Authenticated, can drive every panel action
Controls the response body
Explicitly out of scope: an attacker with root on the box; a compromised Solr; denial of service by sheer traffic volume against the origin web server; and the security of your own web server, PHP build and TLS configuration.
Figure 1 — the trust boundary. The important consequence: there is no point in the pipeline where a log-derived value becomes safe. It is escaped at the sink, every time, in the encoding that sink requires.
Because a security document that only lists strengths is marketing.
- The sign-in lockout is per address, and only per address. That is deliberate rather than an oversight — the reasoning is here — but the cost is that a distributed guesser is not slowed by it at all.
- There is no audit log of panel actions. No record of who looked at what.
- The raw line copy stores complete log lines, including any credential that ended up in a query string on your site. That is your data and your risk; the switch exists so you can decide.
- Enrichment responses are parsed, not verified. A compromised provider could inject a value. It is escaped at every output point, but it can still make a field say something untrue.
- The JA4 field is filled only when your web server logs a JA4 fingerprint (a
ja4variable or anX-JA4header), and no scoring rule reads it yet. - The beacon can be blocked, and a token can be replayed within its window. The signature proves the token was issued by us for that session and that origin — not that this particular client is the one it was issued to. What that buys an attacker is the ability to lie about dwell time for their own session, which is why forged timings are recorded as a signal rather than trusted or dropped.
- No formal third-party security audit has been performed. If you do one, the results are very welcome.
Security
- Reporting a vulnerability
- Threat model
- Controls & hardening