@mukul975/analyzing-api-gateway-access-logs

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,

View in AI SkillSafe app
1 scan finding
0 downloads
0 stars
0 demos
SKILL.md
nameanalyzing-api-gateway-access-logs
descriptionParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
domaincybersecurity
subdomainsecurity-operations
version1.0
authormahipal
licenseApache-2.0

Analyzing API Gateway Access Logs

When to Use

  • When investigating security incidents that require analyzing api gateway access logs
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with security operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

Parse API gateway access logs to identify attack patterns including broken object level authorization (BOLA), excessive data exposure, and injection attempts.

import pandas as pd

df = pd.read_json("api_gateway_logs.json", lines=True)
# Detect BOLA: same user accessing many different resource IDs
bola = df.groupby(["user_id", "endpoint"]).agg(
    unique_ids=("resource_id", "nunique")).reset_index()
suspicious = bola[bola["unique_ids"] > 50]

Key detection patterns:

  1. BOLA/IDOR: sequential resource ID enumeration
  2. Rate limit bypass via header manipulation
  3. Credential scanning (401 surges from single source)
  4. SQL/NoSQL injection in query parameters
  5. Unusual HTTP methods (DELETE, PATCH) on read-only endpoints

Examples

# Detect 401 surges indicating credential scanning
auth_failures = df[df["status_code"] == 401]
scanner_ips = auth_failures.groupby("source_ip").size()
scanners = scanner_ips[scanner_ips > 100]

Embed badges

Add these to your README to show the skill's verification status.

SkillSafe verified badge
Verified badge
[![SkillSafe verified badge](https://api.skillsafe.ai/v1/badge/@mukul975/analyzing-api-gateway-access-logs/verified)](https://skillsafe.ai/skill/@mukul975/analyzing-api-gateway-access-logs/)
Installs badge
Installs badge
[![Installs badge](https://api.skillsafe.ai/v1/badge/@mukul975/analyzing-api-gateway-access-logs/installs)](https://skillsafe.ai/skill/@mukul975/analyzing-api-gateway-access-logs/)
Scan badge
Scan badge
[![Scan badge](https://api.skillsafe.ai/v1/badge/@mukul975/analyzing-api-gateway-access-logs/scan)](https://skillsafe.ai/skill/@mukul975/analyzing-api-gateway-access-logs/)
Eval pass rate badge
Eval pass rate
[![Eval pass rate badge](https://api.skillsafe.ai/v1/badge/@mukul975/analyzing-api-gateway-access-logs/eval)](https://skillsafe.ai/skill/@mukul975/analyzing-api-gateway-access-logs/)