JavaScript is disabled. Some features may not work.
analyzing-api-gateway-access-logs — ★ 19.7K GitHub Stars — Install Guide | SkillsNav
🇺🇸 English🇨🇳 中文
SkillsNav
Home

analyzing-api-gateway-access-logs

★ 19K repogenerationN/AIntermediateClaude
🤖 AI Summary

This skill parses API gateway access logs using Python to detect security threats like BOLA, excessive data exposure, and injection attempts, providing structured procedures for SOC analysts to build detection rules and investigate incidents.

How to Install

Claude Code:
git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git && cp Anthropic-Cybersecurity-Skills/skills/analyzing-api-gateway-access-logs ~/.claude/skills/analyzing-api-gateway-access-logs -r
# Analyzing API Gateway Access Logs ## When to Use - When investigating security incidents that require analyzing api gateway access logs - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques ## Prerequisites - Familiarity with security operations concepts and tools - Access to a test or lab environment for safe execution - Python 3.8+ with required dependencies installed - Appropriate authorization for any testing activities ## Instructions Parse API gateway access logs to identify attack patterns including broken object level authorization (BOLA), excessive data exposure, and injection attempts. ```python import pandas as pd df = pd.read_json("api_gateway_logs.json", lines=True) # Detect BOLA: same user accessing many different resource IDs bola = df.groupby(["user_id", "endpoint"]).agg( unique_ids=("resource_id", "nunique")).reset_index() suspicious = bola[bola["unique_ids"] > 50] ``` Key detection patterns: 1. BOLA/IDOR: sequential resource ID enumeration 2. Rate limit bypass via header manipulation 3. Credential scanning (401 surges from single source) 4. SQL/NoSQL injection in query parameters 5. Unusual HTTP methods (DELETE, PATCH) on read-only endpoints ## Examples ```python # Detect 401 surges indicating credential scanning auth_failures = df[df["status_code"] == 401] scanner_ips = auth_failures.groupby("source_ip").size() scanners = scanner_ips[scanner_ips > 100] ```

Details

Category Coding → generation
Sourcemukul975/Anthropic-Cybersecurity-Skills
SKILL.mdView on GitHub →
Repo Stars★ 19.7K
Est. per SkillN/A (shared across 144 skills from this repo)
DifficultyIntermediate
Risk LevelN/A

Related Skills

Works Well With

Skills from the same repository — often designed to work together