Security monitoring platform developed for Apache web servers in a Windows environment, with real-time analysis of access and error logs, automatic detection of attack patterns and immediate blocking of malicious IPs via Windows Firewall.
The system continuously analyses Apache's access.log and error.log, identifying over 120 catalogued attack patterns — including SQL Injection, Shell Injection, Path Traversal, XSS, framework attacks (Laravel, WordPress, ThinkPHP), known scanners (Nikto, Nmap, Metasploit) and critical exploits such as Log4Shell and Shellshock.
Integration with the AbuseIPDB API enables automatic blocking of IPs with known abuse history on first contact with the server, regardless of the detected attack pattern. The system includes configurable rate limiting, an authorised IP whitelist, maintenance mode with administrative IP protection and intelligent caching of external API queries.
The Windows Presentation Foundation graphical interface presents real-time activity, alert history with severity filters, management of blocked and unblocked IPs, session statistics and auto-blocks. The entire system is compiled as a Windows executable with automatic privilege elevation.