A lightweight Python tool for analyzing authentication logs and detecting suspicious activity such as:
- multiple failed login attempts
- potential bruteβforce attacks
- users with repeated failures
- nightβtime successful logins (22:00β06:00)
- top offending IP addresses
This project is designed as an entryβlevel cyber security portfolio piece, demonstrating log parsing, pattern detection, and basic threat analysis.
log-analyzer/ ββ logs/ β ββ sample_auth.log ββ src/ β ββ log_analyzer.py ββ README.md
The script:
- Reads an authentication log file line by line
- Uses regex to detect:
- FAILED logins
- SUCCESS logins
- Extracts:
- timestamp
- username
- IP address
- Counts failed attempts per IP and per user
- Flags:
- brute force attempts (default: β₯3 failures from same IP)
- successful logins during night hours
- Prints a clean summary in the terminal
Make sure you have Python installed.
Run the analyzer:
python src/log_analyzer.py