Skip to content

Latest commit

Β 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ” Log Analyzer – Suspicious Login Detection Tool

A lightweight Python tool for analyzing authentication logs and detecting suspicious activity such as:

  • multiple failed login attempts
  • potential brute‑force attacks
  • users with repeated failures
  • night‑time successful logins (22:00–06:00)
  • top offending IP addresses

This project is designed as an entry‑level cyber security portfolio piece, demonstrating log parsing, pattern detection, and basic threat analysis.


πŸ“ Project Structure

log-analyzer/ β”œβ”€ logs/ β”‚ └─ sample_auth.log β”œβ”€ src/ β”‚ └─ log_analyzer.py └─ README.md

🧠 How It Works

The script:

  1. Reads an authentication log file line by line
  2. Uses regex to detect:
    • FAILED logins
    • SUCCESS logins
  3. Extracts:
    • timestamp
    • username
    • IP address
  4. Counts failed attempts per IP and per user
  5. Flags:
    • brute force attempts (default: β‰₯3 failures from same IP)
    • successful logins during night hours
  6. Prints a clean summary in the terminal

▢️ Running the Script

Make sure you have Python installed.

Run the analyzer:

python src/log_analyzer.py

About

Python tool for detecting failed logins, brute force attempts and suspicious activity in authentication logs

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages