Back to Security

Internal Tool

Firewall User-Agent Analysis Tool

I designed and built an automated firewall log analysis tool that identifies suspicious User-Agent activity and supports more informed WAF tuning and security investigations.

Role
Application Security Analyst / Sole Designer & Developer
Year
2025–Present
Project type
Internal Tool
An internal automation tool that continuously analyzes firewall logs and highlights suspicious User-Agent activity for further investigation.

THE CHALLENGE

Find meaningful signals in routine firewall noise.

Suspicious User-Agent strings can reveal automated scanners and known attack tooling, but they are easy to miss during manual review of high-volume logs.

THE PIPELINE

Continuously compare traffic against known signatures.

The tool processes F5/WAF logs on a recurring schedule and compares observed values against a maintained database of approximately 1,500 suspicious signatures.

The primary analysis interface highlighting suspicious User-Agent activity.

THE OUTCOME

Give analysts a better starting point.

Rather than replacing judgment, the workflow highlights activity worth investigating and supplies context that can inform future WAF tuning.

Detailed view of analyzed firewall log data.