Threat Engine
26 categories, dual-pass evasion resistance, MITRE-tagged. This page is the honest overview — what is detected, what is not, and where to read the details.
What it does NOT do — limits and false positives
Credibility comes from declaring limits. Read this before trusting a report.
| Limit | Why | What to do |
|---|---|---|
| Pattern-based, not semantic | Looks for known payload substrings, does not execute code | Review grouped IPs — do not auto-block on low confidence |
| Confidence filter | Default --detect-confidence 8 in guard; some hits are 5–6 | Raise to 9 for noisier apps; 0 disables only pattern-based blocks, not guard itself |
| Legitimate paths can look malicious | ?url=https://…, ?code={{var}}, __proto__ in docs | Use --never-block / whitelist and check -f html before blocking |
| Behavioral heuristics need state | ua_rotation, object_enumeration, beaconing need ≥10 samples per IP/path | Run on ≥1h of traffic; single-request logs will not fire them |
| Not a WAF | Offline/log-time detection, not inline request blocking | Use guard to block after detection; do not expect pre-request deny |
| GeoIP/blocklist are best-effort | DB-IP lite + 8 feeds, 7d cache, network required for refresh | Pin --geoip-db and check blocklist list age |
Do not lock yourself out
Every guard example that modifies firewall is marked modifies firewall. On a remote host, always --never-block YOUR_IP. When in doubt, use read-only commands (blocklist list, --detect -f html) first.What it does
- Dual-pass engine — every URI is checked raw and URL-unescaped (split
?+PathUnescape/QueryUnescape+ manual%fallback) to catch%2e%2eand double-encode bypass. Guard runs the sameDetectorper window. - 26 categories — from
sql_injectiontobeaconing, each tagged with verified MITRE ATT&CK IDs. - Grouped by IP — suspicious report shows top IPs with confidence, URI, and techniques.
- Exportable — 23 pattern categories as Sigma rules; 3 behavioral (
ua_rotation,object_enumeration,beaconing) are stateful and not exported.
Where to go next
26 CategoriesConfidence, description and a real fixture example per category — consistent triplet on every row.
MITRE, Sigma & EvasionVerified ATT&CK IDs, 23 Sigma rules, and how dual-pass/markers/literals resist bypass.
GuardWhen detection becomes a block — thresholds, backends, audit and state.
Quick check
caddy-analyze --detect testdata/sample.log
# should list 26 categories firing (68 lines, all TEST-NET)
caddy-analyze --detect -f html -o report.html testdata/large.log && open report.html
caddy-analyze tail docker://caddy --detect # live, severity-colored