analyzing-api-gateway-access-logs
🤖 AI Summary
This skill parses API gateway access logs using Python to detect security threats like BOLA, excessive data exposure, and injection attempts, providing structured procedures for SOC analysts to build detection rules and investigate incidents.
How to Install
Claude Code:
git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git && cp Anthropic-Cybersecurity-Skills/skills/analyzing-api-gateway-access-logs ~/.claude/skills/analyzing-api-gateway-access-logs -r# Analyzing API Gateway Access Logs
## When to Use
- When investigating security incidents that require analyzing api gateway access logs
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
## Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
## Instructions
Parse API gateway access logs to identify attack patterns including broken object
level authorization (BOLA), excessive data exposure, and injection attempts.
```python
import pandas as pd
df = pd.read_json("api_gateway_logs.json", lines=True)
# Detect BOLA: same user accessing many different resource IDs
bola = df.groupby(["user_id", "endpoint"]).agg(
unique_ids=("resource_id", "nunique")).reset_index()
suspicious = bola[bola["unique_ids"] > 50]
```
Key detection patterns:
1. BOLA/IDOR: sequential resource ID enumeration
2. Rate limit bypass via header manipulation
3. Credential scanning (401 surges from single source)
4. SQL/NoSQL injection in query parameters
5. Unusual HTTP methods (DELETE, PATCH) on read-only endpoints
## Examples
```python
# Detect 401 surges indicating credential scanning
auth_failures = df[df["status_code"] == 401]
scanner_ips = auth_failures.groupby("source_ip").size()
scanners = scanner_ips[scanner_ips > 100]
```
Details
| Category | Coding → generation |
| Source | mukul975/Anthropic-Cybersecurity-Skills |
| SKILL.md | View on GitHub → |
| Repo Stars | ★ 19.7K |
| Est. per Skill | N/A (shared across 144 skills from this repo) |
| Difficulty | Intermediate |
| Risk Level | N/A |
Related Skills
pubmed-database
PubMed Database Overview PubMed is the U.S. National Library of Medicine's comprehensive database pr
angular-ui-patterns
Angular UI Patterns Core Principles Never show stale UI - Loading states only when actually loading
cc-skill-continuous-learning
cc-skill-continuous-learning Development skill skill. When to Use This skill is applicable to execut
git-hooks-automation
Git Hooks Automation Automate code quality enforcement at the Git level. Set up hooks that lint, for
Works Well With
Skills from the same repository — often designed to work together
acquiring-disk-image-with-dd-and-dcfldd
Acquiring Disk Image with dd and dcfldd When to Use - When you need to create a forensic copy of a s
analyzing-active-directory-acl-abuse
Analyzing Active Directory ACL Abuse Overview Active Directory Access Control Lists (ACLs) define pe
analyzing-android-malware-with-apktool
Analyzing Android Malware with Apktool Overview Android malware distributed as APK files can be stat