I designed and built an automated firewall log analysis tool that identifies suspicious User-Agent activity and supports more informed WAF tuning and security investigations.
Role
Application Security Analyst / Sole Designer & Developer
Year
2025–Present
Project type
Internal Tool
An internal automation tool that continuously analyzes firewall logs and highlights suspicious User-Agent activity for further investigation.
THE CHALLENGE
Find meaningful signals in routine firewall noise.
Suspicious User-Agent strings can reveal automated scanners and known attack tooling, but they are easy to miss during manual review of high-volume logs.
THE PIPELINE
Continuously compare traffic against known signatures.
The tool processes F5/WAF logs on a recurring schedule and compares observed values against a maintained database of approximately 1,500 suspicious signatures.
The primary analysis interface highlighting suspicious User-Agent activity.
THE OUTCOME
Give analysts a better starting point.
Rather than replacing judgment, the workflow highlights activity worth investigating and supplies context that can inform future WAF tuning.