Attack patterns

A request that matches is flagged on the Attacks page and its visit is scored a bot.

Attack patterns name requests that are an attack on your sites, on top of the detector built into Loghound. A request that matches is shown as Your attack pattern on the Attacks page, and the visit that made it is scored a bot on that alone.

A match is a verdict

Add only what no real visitor of that host could ever request. /wp-json/ on a site that runs no WordPress is a good example; on a WordPress site it would convict your own readers.

01 · Your patterns
  1. Open Settings › Attack patterns.
  2. Under Your patterns, pick a Hostname, or leave it empty for every host.
  3. Pick a Kind. Text matches anywhere in the decoded path and query string, ignoring case. Regular expression is a pattern with no slashes and no flags; one that does not compile is refused when you save.
  4. Type the Pattern and press Save attack patterns.

Up to 200 patterns, each up to 200 characters. The reader applies them from its next restart or reload. A request is flagged when it is read, so a change never rewrites what is already indexed.

02 · Shipped with Loghound

48 defaults that are an attack on any website: webshell file names, exposed secrets and deployment files (.git, environment and credential files, CI configuration, database dumps, site backup archives) and botnet droppers. They apply to every host.

  • Untick a default to switch it off. It stays off after an update.
  • Anything that is a real path for somebody, such as /wp-admin, is deliberately not a default. Add it yourself for the hosts that do not run that software.

What a match looks like afterwards: the Attacks view. How it is scored: the Exploit probe rule in Rules decisive alone. To copy your patterns to another installation: Rule lists as CSV.

Settings

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation