Back to Cheat Sheets

🛡️ Insufficient Logging & MonitoringOWASP 2017

OWASP WEB Top 10 2017 - #10

MEDIUM RISK

📋 What Is It?

Insufficient Logging & Monitoring - Insufficient logging and monitoring, coupled with missing or ineffective integration with incident response, allows attackers to further attack systems, maintain persistence, pivot to more systems, and tamper, extract, or destroy data.

#10 OWASP Rank 2017
6% Apps Tested
73K Occurrences

⚠️ Common Exploits

  • Undetected Breaches: Attack without detection
  • Log Tampering: Modify or delete logs
  • Extended Dwell Time: Persist for months
  • Privilege Escalation: Escalate undetected
  • Data Exfiltration: Steal data over time

🔴 Attack Flow

1. Attacker gains initial access

2. Performs reconnaissance activities

3. No alerts or monitoring triggers

4. Escalates privileges and exfiltrates data

5. BREACH: Months pass before detection!

✓ Prevention Checklist

  • Log all authentication and authorization events
  • Ensure logs are immutable and tamper-proof
  • Implement real-time monitoring and alerting
  • Establish incident response procedures
  • Use SIEM for log aggregation and analysis

📌 Quick Reference

Risk Level: MEDIUM RISK
Year: OWASP Top 10 2017
Category: WEB
Ranking: #10 in 2017