Articles
Choosing concurrency for DenyHosts log processingDenyHosts protects SSH services by examining authentication logs, identifying repeated attack sources, and updating host-based deny lists. That workflow…
How I Designed Kodos for Linux Clipboard WorkflowsKodos began with a practical goal: make regular expression development feel immediate. Instead of switching between an editor, a shell, test data, and…
How Scratchy Categorizes Bot Traffic vs Human Traffic in Apache LogsApache access logs record every request in a compact, machine-readable format. That raw stream can reveal popular pages, broken links, hostile probes, crawler…
How I Tested DenyHosts Against Custom Brute Force Simulation ScriptsDenyHosts is designed to watch SSH authentication activity, identify repeated failures, and maintain a list of hosts that should be blocked. I wanted to…
The Design Decisions Behind DenyHosts Default Deny ThresholdsDenyHosts was built around a simple operational problem: an internet-facing SSH service can receive a large number of automated login attempts before an…
Tracing Coordinated Intrusions with Scratchy Forensic AnalysisWhen a web server starts returning unusual traffic patterns, the first challenge is separating a genuine attack from the constant noise of the public internet.…
How I Optimized Scratchy for Gigabyte-Sized Apache LogsScratchy began as a focused Apache log analyzer: read access logs, extract useful fields, and turn raw request data into reports. That workflow worked well for…
Designing Scratchy to Detect and Highlight Anomalous Traffic SpikesApache access logs contain a detailed record of how a server is being used: client addresses, request paths, response codes, referrers, user agents,…
Auditing Server Access With Scratchy After a Security IncidentWhen a web server has been compromised or subjected to a suspected attack, its access logs can provide the first reliable account of what happened. They record…
How Scratchy Processes Log Files With Multiple Unclosed EntriesLog files are often treated as orderly streams of completed records, but real server output is less predictable. Processes can stop during a write, files can…
