Attack patterns name requests that are an attack on your sites, on top of the detector built into Loghound. A request that matches is shown as Your attack pattern on the Attacks page, and the visit that made it is scored a bot on that alone.
Add only what no real visitor of that host could ever request. /wp-json/ on a site that runs no WordPress is a good example; on a WordPress site it would convict your own readers.
- Open Settings › Attack patterns.
- Under Your patterns, pick a Hostname, or leave it empty for every host.
- Pick a Kind. Text matches anywhere in the decoded path and query string, ignoring case. Regular expression is a pattern with no slashes and no flags; one that does not compile is refused when you save.
- Type the Pattern and press Save attack patterns.
Up to 200 patterns, each up to 200 characters. The reader applies them from its next restart or reload. A request is flagged when it is read, so a change never rewrites what is already indexed.
48 defaults that are an attack on any website: webshell file names, exposed secrets and deployment files (.git, environment and credential files, CI configuration, database dumps, site backup archives) and botnet droppers. They apply to every host.
- Untick a default to switch it off. It stays off after an update.
- Anything that is a real path for somebody, such as
/wp-admin, is deliberately not a default. Add it yourself for the hosts that do not run that software.
What a match looks like afterwards: the Attacks view. How it is scored: the Exploit probe rule in Rules decisive alone. To copy your patterns to another installation: Rule lists as CSV.