---
name: API Gateway Log Analysis
slug: api-gateway-log-analysis
category: Data
description: API Gateway Log Analysis parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect attack patterns such as BOLA, excessive data exposure, and injection attempts. Use it when investigating security incidents or building detection rules.
github: "https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/analyzing-api-gateway-access-logs"
language: Python
stars: 27758
forks: 3369
install: "npx degit https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/analyzing-api-gateway-access-logs ~/.claude/skills/analyzing-api-gateway-access-logs"
installs_to: ~/.claude/skills/analyzing-api-gateway-access-logs
source_path: skills/analyzing-api-gateway-access-logs/SKILL.md
collection_size: 25
category_size: 668
collection_url: "https://dirskills.com/collections/mukul975/Anthropic-Cybersecurity-Skills"
added: 2026-08-14T07:11:54.349Z
last_synced: 2026-08-14T07:11:54.349Z
canonical_url: "https://dirskills.com/skills/api-gateway-log-analysis"
---

# API Gateway Log Analysis

API Gateway Log Analysis parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect attack patterns such as BOLA, excessive data exposure, and injection attempts. Use it when investigating security incidents or building detection rules.

**Install:**

```bash
npx degit https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/analyzing-api-gateway-access-logs ~/.claude/skills/analyzing-api-gateway-access-logs
```

## README

# Analyzing API Gateway Access Logs


## When to Use

- When investigating security incidents that require analyzing api gateway access logs
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques

## Prerequisites

- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities

## Instructions

Parse API gateway access logs to identify attack patterns including broken object
level authorization (BOLA), excessive data exposure, and injection attempts.

```python
import pandas as pd

df = pd.read_json("api_gateway_logs.json", lines=True)
# Detect BOLA: same user accessing many different resource IDs
bola = df.groupby(["user_id", "endpoint"]).agg(
    unique_ids=("resource_id", "nunique")).reset_index()
suspicious = bola[bola["unique_ids"] > 50]
```

Key detection patterns:
1. BOLA/IDOR: sequential resource ID enumeration
2. Rate limit bypass via header manipulation
3. Credential scanning (401 surges from single source)
4. SQL/NoSQL injection in query parameters
5. Unusual HTTP methods (DELETE, PATCH) on read-only endpoints

## Examples

```python
# Detect 401 surges indicating credential scanning
auth_failures = df[df["status_code"] == 401]
scanner_ips = auth_failures.groupby("source_ip").size()
scanners = scanner_ips[scanner_ips > 100]
```
