Loading
0xA0Lesson 11 of 13

Log, detect and alert

Record the right security events, keep secrets out of logs, and turn patterns into alerts.

22 min 5-question quiz 2 code exercises
By the end of this lesson you can
  • Decide which security events to log and what to leave out
  • Read logs for signs of attack
  • Write a detection rule and think about false positives

You can’t respond to what you never see. Security Logging and Alerting Failures are A09 in the OWASP Top 10:2025: many breaches go unnoticed for months because nothing recorded the attack, or nobody looked.

Log security-relevant events with who, what, when, where and the outcome: sign-ins (success and failure), MFA changes, password resets, permission changes, access denied, admin actions, input validation failures and unusual errors.

Don’t log passwords, session tokens, API keys, full card numbers or unnecessary personal data - logs are copied widely and kept long, so they become a target themselves. Mask or redact instead.

Try it

Read the logs like an analyst

Click the lines that deserve a closer look.

Sign-in log (1 of 2)Flags found 0/0

Click every part that looks suspicious. There are 4.

22:01:07 login success user=tom ip=198.51.100.20 (Lisbon) 22:03:11 login fail user=maria ip=203.0.113.50 22:03:12 login fail user=maria ip=203.0.113.50 22:03:13 login fail user=maria ip=203.0.113.50 22:03:14 login fail user=maria ip=203.0.113.50 22:03:15 login success user=maria ip=203.0.113.50 22:04:02 login success user=ana ip=198.51.100.31 (Lisbon) 22:05:40 mfa disabled user=maria ip=203.0.113.50 22:06:00 login success user=ana ip=192.0.2.77 (Jakarta) 22:10:12 password reset user=tom ip=198.51.100.20 (Lisbon)

From logs to alerts

A detection rule turns a pattern into an alert - for example “5 failed sign-ins from one IP within 60 seconds”. Every rule trades off:

  • false positives (alerts on innocent activity, which burn analysts out and get ignored), against
  • false negatives (missed attacks - like a slow attacker trying one password per minute).

Teams centralize logs in a SIEM, map rules to attacker techniques (the MITRE ATT&CK knowledge base is the common vocabulary), and tune rules over time.

sliding_window.py
1from collections import deque
2window = deque()
3for time in [0, 10, 20, 30, 45, 200]:
4    window.append(time)
5    while time - window[0] > 60:
6        window.popleft()
7    print(time, len(window))
Output
0 1
10 2
20 3
30 4
45 5
200 1

Key takeaways

  • Log security events with who, what, when, where and outcome - never secrets.

  • Bursts of failures, success after failures, impossible travel and odd exports deserve attention.

  • Detection rules balance false positives against missed attacks; tune them.

Lesson quiz

5 questions · pass with 4 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Practice: write Python

Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.

Exercise 1

Detect password guessing

+25 XP

Each line is SECONDS IP USER RESULT (result fail or success), in time order.

  • Keep each IP’s failures from the last 60 seconds (a failure at time t counts while now - t <= 60).
  • When an IP reaches 5 such failures, print ALERT IP: 5 failures within 60s at t=SECONDS - once per IP.
  • On a success, if that IP has 3 or more failures in its window, print CHECK USER logged in from IP after N recent failures.
  • A fast attacker and a slow one
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Exercise 2

Redact log lines

+25 XP

Before writing each input line to the log, redact:

  • email addresses → first character, ***, then @domain (a***@example.com);
  • Bearer TOKEN → Bearer [REDACTED];
  • runs of 13-16 digits (card numbers) → * for all but the last 4 digits.
  • Three lines
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Did you like the lesson? 😆👍
Consider a donation to support our work: