ModSecurity

ModSecurity WAF
Cache: 19:22:17 Refresh
ModSecurity Active
Today
2444
Blocked
142
Total in sample
2444
Unique IPs
10
Rule list unavailable — update the monitor-modsec wrapper and add the ---RULES--- section (see FAQ).
Attack types
Scanner
13
Protocol Attack
11
SQL Injection
11
RCE
10
LFI/Path Traversal
10
XSS
7
Top attacking IPs
IPEvents
198.51.100.326
198.51.100.315
198.51.100.245
198.51.100.285
198.51.100.184
198.51.100.254
198.51.100.204
198.51.100.164
198.51.100.193
198.51.100.333
Top target URLs
URIEvents
/admin/11
/wp-login.php11
/api/v1/login10
/xmlrpc.php9
/?q=../../etc/passwd8
/index.php?id=17
/.env6
Top triggered rules
Rule IDHits
913100
Security scanner — User-Agent
18
942100
SQL Injection via libinjection
14
941100
XSS via libinjection
13
930100
Path Traversal (/../)
10
932100
RCE — Unix commands
7
Recent events 62 entries
TimeIPURITypeRuleAction
2026-10-11 19:22:17 198.51.100.18 /?q=../../etc/passwd Protocol Attack 932100
RCE — Unix commands
Detected
2026-10-11 18:49:37 198.51.100.13 /admin/ XSS 930100
Path Traversal (/../)
Detected
2026-10-11 19:01:33 198.51.100.19 /wp-login.php XSS 942100
SQL Injection via libinjection
Blocked
2026-10-11 17:46:53 198.51.100.31 /api/v1/login Protocol Attack 913100
Security scanner — User-Agent
Detected
2026-10-11 18:47:53 198.51.100.25 /xmlrpc.php Scanner 913100
Security scanner — User-Agent
Detected
2026-10-11 18:30:47 198.51.100.18 /xmlrpc.php RCE 942100
SQL Injection via libinjection
Blocked
2026-10-11 16:58:59 198.51.100.11 /.env Scanner 932100
RCE — Unix commands
Detected
2026-10-11 18:01:47 198.51.100.20 /wp-login.php SQL Injection 942100
SQL Injection via libinjection
Blocked
2026-10-11 16:53:53 198.51.100.26 /api/v1/login Protocol Attack 913100
Security scanner — User-Agent
Blocked
2026-10-11 18:41:11 198.51.100.30 /api/v1/login SQL Injection 913100
Security scanner — User-Agent
Detected
2026-10-11 14:40:57 198.51.100.31 /api/v1/login Scanner 913100
Security scanner — User-Agent
Blocked
2026-10-11 14:37:34 198.51.100.32 /xmlrpc.php SQL Injection 913100
Security scanner — User-Agent
Detected
2026-10-11 18:00:17 198.51.100.30 /.env Scanner 913100
Security scanner — User-Agent
Detected
2026-10-11 14:10:30 198.51.100.24 /wp-login.php LFI/Path Traversal 930100
Path Traversal (/../)
Detected
2026-10-11 13:53:03 198.51.100.20 /api/v1/login LFI/Path Traversal 942100
SQL Injection via libinjection
Detected
2026-10-11 18:03:32 198.51.100.35 /index.php?id=1 Protocol Attack 941100
XSS via libinjection
Blocked
2026-10-11 17:00:57 198.51.100.18 /xmlrpc.php SQL Injection 941100
XSS via libinjection
Detected
2026-10-11 12:27:29 198.51.100.35 /wp-login.php XSS 941100
XSS via libinjection
Blocked
2026-10-11 11:52:35 198.51.100.25 /.env RCE 913100
Security scanner — User-Agent
Blocked
2026-10-11 15:32:42 198.51.100.31 /admin/ Protocol Attack 941100
XSS via libinjection
Detected
2026-10-11 15:10:17 198.51.100.18 /admin/ Scanner 942100
SQL Injection via libinjection
Detected
2026-10-11 09:27:17 198.51.100.31 /.env LFI/Path Traversal 932100
RCE — Unix commands
Detected
2026-10-11 17:09:55 198.51.100.29 /.env SQL Injection 942100
SQL Injection via libinjection
Blocked
2026-10-11 17:26:54 198.51.100.31 /?q=../../etc/passwd Scanner 913100
Security scanner — User-Agent
Detected
2026-10-11 12:08:17 198.51.100.25 /index.php?id=1 Protocol Attack 913100
Security scanner — User-Agent
Detected
2026-10-11 10:14:47 198.51.100.25 /xmlrpc.php RCE 942100
SQL Injection via libinjection
Blocked
2026-10-11 08:16:15 198.51.100.28 /admin/ Protocol Attack 941100
XSS via libinjection
Detected
2026-10-11 06:52:35 198.51.100.33 /api/v1/login Scanner 930100
Path Traversal (/../)
Detected
2026-10-11 16:03:01 198.51.100.16 /.env Protocol Attack 942100
SQL Injection via libinjection
Detected
2026-10-11 04:45:02 198.51.100.21 /?q=../../etc/passwd Scanner 941100
XSS via libinjection
Detected
2026-10-11 11:59:47 198.51.100.13 /?q=../../etc/passwd XSS 930100
Path Traversal (/../)
Detected
2026-10-11 13:40:46 198.51.100.33 /?q=../../etc/passwd XSS 930100
Path Traversal (/../)
Detected
2026-10-11 08:16:41 198.51.100.32 /admin/ Protocol Attack 913100
Security scanner — User-Agent
Blocked
2026-10-11 09:56:20 198.51.100.32 /?q=../../etc/passwd SQL Injection 941100
XSS via libinjection
Blocked
2026-10-11 09:27:51 198.51.100.24 /?q=../../etc/passwd Scanner 942100
SQL Injection via libinjection
Detected
2026-10-11 09:59:22 198.51.100.12 /admin/ LFI/Path Traversal 913100
Security scanner — User-Agent
Blocked
2026-10-11 16:03:41 198.51.100.19 /api/v1/login Protocol Attack 913100
Security scanner — User-Agent
Detected
2026-10-11 13:42:30 198.51.100.28 /wp-login.php SQL Injection 932100
RCE — Unix commands
Detected
2026-10-11 00:08:21 198.51.100.28 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Detected
2026-10-11 16:48:14 198.51.100.24 /xmlrpc.php SQL Injection 930100
Path Traversal (/../)
Detected
2026-10-11 13:47:37 198.51.100.32 /admin/ LFI/Path Traversal 913100
Security scanner — User-Agent
Detected
2026-10-11 00:01:18 198.51.100.16 /wp-login.php RCE 941100
XSS via libinjection
Detected
2026-10-11 02:46:53 198.51.100.28 /index.php?id=1 RCE 932100
RCE — Unix commands
Blocked
2026-10-10 21:23:37 198.51.100.26 /wp-login.php XSS 941100
XSS via libinjection
Detected
2026-10-11 10:21:05 198.51.100.29 /wp-login.php LFI/Path Traversal 942100
SQL Injection via libinjection
Detected
2026-10-11 09:56:02 198.51.100.32 /api/v1/login SQL Injection 913100
Security scanner — User-Agent
Detected
2026-10-11 07:57:39 198.51.100.34 /index.php?id=1 RCE 930100
Path Traversal (/../)
Detected
2026-10-11 00:28:01 198.51.100.15 /api/v1/login SQL Injection 930100
Path Traversal (/../)
Detected
2026-10-10 20:18:17 198.51.100.20 /xmlrpc.php Scanner 913100
Security scanner — User-Agent
Detected
2026-10-11 01:34:05 198.51.100.28 /wp-login.php RCE 942100
SQL Injection via libinjection
Blocked
2026-10-11 12:46:27 198.51.100.22 /wp-login.php Scanner 941100
XSS via libinjection
Detected
2026-10-11 14:26:29 198.51.100.34 /index.php?id=1 XSS 932100
RCE — Unix commands
Blocked
2026-10-11 07:55:53 198.51.100.21 /admin/ RCE 942100
SQL Injection via libinjection
Detected
2026-10-11 13:08:38 198.51.100.20 /wp-login.php LFI/Path Traversal 930100
Path Traversal (/../)
Detected
2026-10-10 16:03:23 198.51.100.32 /index.php?id=1 Scanner 932100
RCE — Unix commands
Detected
2026-10-10 15:47:42 198.51.100.23 /admin/ RCE 942100
SQL Injection via libinjection
Detected
2026-10-11 09:06:17 198.51.100.33 /index.php?id=1 Protocol Attack 913100
Security scanner — User-Agent
Detected
2026-10-11 12:44:14 198.51.100.16 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Detected
2026-10-10 23:07:11 198.51.100.19 /xmlrpc.php Scanner 941100
XSS via libinjection
Blocked
2026-10-10 11:50:21 198.51.100.24 /admin/ LFI/Path Traversal 941100
XSS via libinjection
Detected
2026-10-10 22:51:17 198.51.100.16 /api/v1/login LFI/Path Traversal 930100
Path Traversal (/../)
Detected
2026-10-11 14:43:43 198.51.100.24 /admin/ SQL Injection 941100
XSS via libinjection
Detected

A ModSecurity log viewer for the audit log

ModSecurity with the OWASP Core Rule Set blocks a great deal, and writes about all of it to an audit log in a format built for machines. This page turns that log into something readable: which requests were blocked, which rule fired, what the anomaly score was, and where the request came from.

The reason to look at this regularly is false positives. The Core Rule Set is deliberately strict, and at the default paranoia level it will block legitimate traffic in most real applications — file uploads, rich text editors, and anything that posts markup or SQL-like strings are the usual casualties. The pattern to look for is the same rule ID firing repeatedly against the same endpoint from many different addresses. That is not an attack, that is your own application being caught.

Whitelist narrowly when you find one: exclude the specific rule for the specific parameter on the specific path, not the whole rule and never the whole category. The page also lists the active rule set so you can confirm what is actually loaded after a change.