Skip to main content

System log analyzer for detecting suspicious activities

Project description

LogHero ๐Ÿฆธโ€โ™‚๏ธ

System Log Security Analyzer

Developed by Ahmet KAHRAMAN (AhmetXHero) - Mobile Developer & Cyber Security Expert

LogHero is a powerful command-line tool designed to analyze system log files and detect suspicious security activities. It specializes in identifying SSH brute-force attacks, unauthorized root access attempts, and other security threats across Linux, Windows, and macOS systems.

๐ŸŽฏ Features

  • SSH Brute-Force Detection: Identifies repeated failed SSH login attempts from the same IP
  • Root Access Monitoring: Detects unauthorized attempts to gain root privileges
  • Multi-OS Support: Works with Linux, Windows, and macOS log formats
  • Real-time Analysis: Fast log parsing and threat detection
  • Detailed Reporting: Comprehensive security reports with recommendations
  • Flexible Output: Table, JSON, and CSV output formats
  • Batch Processing: Analyze multiple log files at once

๐Ÿš€ Installation

From PyPI (Recommended)

pip install AhmetX-LogHero

From Source

git clone https://github.com/ahmetxhero/AhmetX-LogHero.git
cd loghero
pip install -e .

๐Ÿ“‹ Requirements

  • Python 3.7+
  • Dependencies: click, colorama, python-dateutil, tabulate

๐Ÿ›  Usage

Basic Usage

# Analyze a single log file
loghero scan /var/log/auth.log

# Analyze with specific severity filter
loghero scan /var/log/secure --severity HIGH

# Output in JSON format
loghero scan /var/log/auth.log --output json

# Save detailed report
loghero scan /var/log/auth.log --save-report security_report.json

Batch Analysis

# Analyze all log files in a directory
loghero batch /var/log

# Analyze with specific pattern
loghero batch /var/log --pattern "auth*" --recursive

Command Options

loghero scan

  • --output, -o: Output format (table, json, csv)
  • --severity, -s: Filter by minimum severity (LOW, MEDIUM, HIGH, CRITICAL)
  • --threat-type, -t: Filter by specific threat type
  • --limit, -l: Limit number of results (default: 50)
  • --quiet, -q: Suppress banner and extra output
  • --save-report: Save detailed report to file

loghero batch

  • --pattern, -p: File pattern to match (default: *.log)
  • --recursive, -r: Search recursively in subdirectories

๐Ÿ” Detected Threats

SSH Brute-Force Attacks

  • Failed password attempts
  • Failed public key authentication
  • Invalid user attempts
  • Suspicious connection patterns

Root Access Violations

  • Failed su attempts to root
  • Unauthorized sudo usage
  • Direct root login attempts
  • Privilege escalation attempts

Authentication Failures

  • Repeated login failures
  • PAM authentication errors
  • System authentication violations

๐Ÿ“Š Example Output

โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘                          LogHero v1.0.0                     โ•‘
โ•‘                  System Log Security Analyzer               โ•‘
โ•‘              Detecting suspicious activities...             โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

๐Ÿ“ Analyzing log file: /var/log/auth.log

๐Ÿ“Š Analysis Summary:
   โ€ข Total log entries processed: 15,432
   โ€ข Total threats found: 23
   โ€ข Unique source IPs: 8

๐Ÿšจ Security Threats Detected:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Timestamp           โ”‚ Severity โ”‚ Type                โ”‚ Source IP   โ”‚ Description                      โ”‚ Count โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ 2024-01-15 14:23:45 โ”‚ CRITICAL โ”‚ SSH_BRUTE_FORCE     โ”‚ 192.168.1.100โ”‚ SSH brute-force attack: 25 fail...โ”‚ 25    โ”‚
โ”‚ 2024-01-15 13:45:12 โ”‚ HIGH     โ”‚ ROOT_LOGIN_ATTEMPT  โ”‚ 10.0.0.50   โ”‚ Failed direct root login attemptโ”‚ 1     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐ŸŽฏ Top Threatening IPs:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ IP Address      โ”‚ Threats โ”‚ Score โ”‚ Types               โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ 192.168.1.100   โ”‚ 25      โ”‚ 100   โ”‚ SSH_BRUTE_FORCE     โ”‚
โ”‚ 10.0.0.50       โ”‚ 3       โ”‚ 9     โ”‚ ROOT_LOGIN_ATTEMPT  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ’ก Security Recommendations:
   1. Consider implementing fail2ban to automatically block IPs
   2. Use SSH key authentication instead of passwords
   3. Disable direct root login via SSH
   4. Implement SSH rate limiting
   5. Set up real-time alerts for security events

๐Ÿ—‚ Supported Log Formats

Linux

  • /var/log/auth.log (Debian/Ubuntu)
  • /var/log/secure (RedHat/CentOS)
  • /var/log/syslog
  • Custom syslog formats

macOS

  • /var/log/system.log
  • /var/log/auth.log
  • Console app logs

Windows

  • Security Event Logs
  • Application Event Logs
  • System Event Logs

๐Ÿ”ง Configuration

LogHero works out of the box with sensible defaults, but you can customize detection thresholds:

SSH Brute-Force Detection

  • Default threshold: 5 failed attempts
  • Default time window: 300 seconds (5 minutes)

Root Access Detection

  • Monitors all su, sudo, and direct root login attempts
  • Flags suspicious administrative commands

๐Ÿค Contributing

We welcome contributions! Please see our Contributing Guide for details.

Development

Test PyPI'dan install et

pip install --index-url https://test.pypi.org/simple/ AhmetX-LogHero/loghero.git cd loghero pip install -e ".[dev]"

Running Tests

pytest tests/

๐Ÿ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

๐Ÿ†˜ Support

๐Ÿ™ Acknowledgments

  • Thanks to the cybersecurity community for threat intelligence
  • Inspired by fail2ban and other security monitoring tools
  • Built with love for system administrators and security professionals

๐Ÿ‘จโ€๐Ÿ’ป About the Developer

Ahmet KAHRAMAN (AhmetXHero) is a Mobile Developer & Cyber Security Expert with 10+ years of experience in Public Sector IT. He specializes in:

  • ๐Ÿ“ฑ Mobile Development: iOS, Android, Flutter, React Native
  • ๐Ÿ”’ Cybersecurity: Digital Forensics, Penetration Testing, Security Analysis
  • ๐ŸŽ“ Education: Master's in Forensic Informatics, Multiple certifications
  • ๐ŸŒ Connect: Portfolio | YouTube | LinkedIn

"Security first, innovation always" ๐Ÿš€


โš ๏ธ Security Notice: LogHero is a detection tool. Always implement proper security measures like firewalls, intrusion prevention systems, and regular security updates alongside log monitoring.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ahmetx_loghero-1.0.0.tar.gz (14.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ahmetx_loghero-1.0.0-py3-none-any.whl (15.4 kB view details)

Uploaded Python 3

File details

Details for the file ahmetx_loghero-1.0.0.tar.gz.

File metadata

  • Download URL: ahmetx_loghero-1.0.0.tar.gz
  • Upload date:
  • Size: 14.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for ahmetx_loghero-1.0.0.tar.gz
Algorithm Hash digest
SHA256 061bf456bfa084d5b8be8449f510fd9126a8f7d48021b6abf431ce773a537598
MD5 ce54954bad6c8918e476ccfddee5bedd
BLAKE2b-256 924de5fb2d47d66ca404088fbdec1b86b10cc521985d7c9a48ab0c398f17aa0d

See more details on using hashes here.

File details

Details for the file ahmetx_loghero-1.0.0-py3-none-any.whl.

File metadata

  • Download URL: ahmetx_loghero-1.0.0-py3-none-any.whl
  • Upload date:
  • Size: 15.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for ahmetx_loghero-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cbfc749f6a9c825aff6aa7bd4763d795ea350824693ae30d8b1e1c7efebcc4ee
MD5 8e6414f29729da570f2842e2b170b62e
BLAKE2b-256 bf37dc401b15a1a4cdceeb02e853e7d5e610dc67e12055cfd38b67d39bb70490

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page