This repository documents the knowledge and experience I gained while detecting, analyzing, and investigating web attacks using logs, HTTP traffic, and SIEM alerts on the LetsDefend platform.
- SQL Injection
- Cross site scripting (XSS)
- Command injection
- Insecure Direct Object Reference (IDOR)
- Local File Inclusion (LFI)
- Open Redirection
- Directory Traversal
- Brute Force
- XML External Entity (XEE) Injection
- Server side template injection (SSTI)
- Expression Language Injection (ELI)
- Server side template injection (SSTI)
- HTTP Header Injection
- Server Side Request Forgery (SSRF)
- NoSQL Injection
- Application Server Attacks
- Web Shells
- Text4Shell
- Log4Shell
- F5-Big-IP
- JSON Web Token (JWT) Vulnerabilities
- SAML Vulnerabilities
- Deserialization Vulnerabilities
- Spring4Shell
- Analyzing Common Attacks
This repo is based on my learnings from the LetsDefend Web Attack Detection and Analysis Path.