Settings

The log

Drop a log file here, or open one auth.log / secure, or an Apache/nginx access log. Nothing is uploaded.

How to read this

Addresses are ordered worst first: a login after failures and requests carrying a payload sit above raw scanning. It reads volume and signature, not intent, so confirm before blocking - a busy legitimate client can look like a scanner, and a slow attack can stay under the line. Export the list to feed a block list, and keep the raw log with CHAIN if it may be evidence.