Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
Nginx Watcher

Log'larından Saldırıyı Yakala,
Toplulukla Paylaş
Catch Attacks From Your Logs,
Share With the Community

Nginx Watcher, SiberKapan platformuyla entegre çalışan açık kaynak bir log izleme agent'ıdır. Tek komutla kur — nginx access log'unu canlı izler, 404/auth flood, exploit path imzaları ve scanner User-Agent'larını tespit eder, saldırgan IP'leri otomatik olarak SiberKapan'a bildirir. Nginx Watcher is an open-source log monitoring agent that integrates with the SiberKapan platform. Install with one command — it monitors your nginx access log in real time, detects 404/auth floods, exploit path signatures, and scanner User-Agents, and automatically reports attacker IPs to SiberKapan.

Kurulum — tek komut Installation — single command
$ curl -fsSL https://siberkapan.org/nginx-watcher/install.sh | sudo bash -s -- --key=API_ANAHTARINIZ
Canlı Nginx Watcher İstatistikleri Live Nginx Watcher Statistics
30861
Toplam Tespit Edilen Olay Total Detected Events
8305
Unique Saldırgan IP Unique Attacker IPs
3
Aktif Watcher Agent'ı Active Watcher Agents
PATH SIGNATURE
En Sık Görülen Pattern Most Common Pattern

Pattern Bazlı Tespit Dağılımı Detections by Pattern

PATH SIGNATURE
24996
404 FLOOD
3016
RATE FLOOD
1518
UA SIGNATURE
973
AUTH FLOOD
325
MALFORMED REQUEST
27
RATE LIMIT FLOOD
6

Son Yakalanan IP'ler Recently Captured IPs

IPIP PatternPattern ÜlkeCountry TekrarHits Son GörülmeLast Seen
5.250.255.207 RATE LIMIT FLOOD Türkiye x6 23.09 14:07
91.217.249.211 PATH SIGNATURE x1 23.09 14:06
45.198.224.188 PATH SIGNATURE x18 23.09 14:04
91.92.242.223 PATH SIGNATURE The Netherlands x1978 23.09 13:58
80.2.118.0 PATH SIGNATURE x3 23.09 13:44
144.172.109.237 PATH SIGNATURE x3 23.09 13:38
154.127.254.98 PATH SIGNATURE x2 23.09 13:38
91.214.139.152 PATH SIGNATURE x1 23.09 13:38
20.64.97.174 UA SIGNATURE x2 23.09 13:34
194.28.89.218 PATH SIGNATURE x23 23.09 13:25
Nasıl Çalışır? How Does It Work?
1
⬇️
Kur Install
Sunucuna tek komutla kur. SiberKapan API anahtarını gir, agent otomatik olarak systemd servisi olarak başlar. Install on your server with a single command. Enter your SiberKapan API key, and the agent starts automatically as a systemd service.
2
🔍
İzle ve Tespit Et Watch and Detect
nginx access log'unu canlı izler. 404/auth/rate flood, exploit path imzaları ve scanner UA'larını anlık tespit eder. Monitors your nginx access log in real time. Instantly detects 404/auth/rate floods, exploit path signatures, and scanner UAs.
3
🛡️
Topluluğu Koru Protect Community
Eşik aşılınca SiberKapan'a otomatik bildirim. Saldırgan IP tüm toplulukla ve AbuseIPDB ile paylaşılır. Automatic report to SiberKapan once a threshold is crossed. Attacker IP is shared with the community and AbuseIPDB.
Saldırgan          Nginx               Nginx Watcher        SiberKapan
    │                   │                    │                    │
    │── GET /wp-login.php ▶│                    │                    │
    │                   │── access.log ──────▶│                    │
    │◀──────────── 404 Not Found ─────────────│                    │
    │                                         │ Pattern eşleşti:   │
    │                                         │ path_signature     │
    │                                         │── POST /feed/ ────▶│
    │                                         │   nginx             │
    │                                         │                    │── DB'ye ekle
    │                                         │                    │── AbuseIPDB'ye raporla
                                                                   Tüm topluluk korunur
Tespit Edilen Pattern'ler Detected Patterns
404

404 Flood

Dizin/endpoint taramaDirectory/endpoint scanning

401/403

Auth Flood

Brute-force giriş denemesiBrute-force login attempts

RATE

Rate Flood

Bot/scanner istek hızıBot/scanner request rate

PATH

Path Signature

Bilinen exploit imzalarıKnown exploit signatures

UA

UA Signature

sqlmap, nikto, nmap vb.sqlmap, nikto, nmap, etc.

Başlamak İçin API Anahtarı Gerekiyor An API Key Is Required to Get Started

SiberKapan'a ücretsiz kayıt olun, API anahtarınızı alın ve kuruluma başlayın. Register for free on SiberKapan, get your API key, and start the installation.