Free Website Security Audit for NZ Businesses | Moat AIS
Free · No Account Required · NZ Businesses

Find out what's
attacking your website.

Upload your web server access log and we'll crawl your site, classify every request against our AI blueprint engine, and email you a detailed threat report. It costs nothing, and you won't need an account.

Get my free threat report

Takes less than 5 minutes  ·  Standalone HTML report emailed to you

80.7%
Of traffic was attacks
6,279
Attacks detected
108
IPs to ban
762
Unique IPs analysed
Moat AIS threat report for a New Zealand website showing 9,947 requests analysed, 6,279 attacks detected, 80.7% attack traffic

Real threat report for a New Zealand website, where 80.7% of all traffic turned out to be attacks. Your report will show your own data.

Three steps to your report

The whole thing runs on its own once you submit your domain and upload your log.

1

Enter your domain & email

Submit your website's domain name and email address, and we start crawling your site right away to build a blueprint of what legitimate traffic looks like.

2

Upload your access log

Once we've crawled your site, we'll email you a secure upload link. Drop in your web server access log, whether that's nginx, Apache, or a cPanel download. .log, .gz, .zip, and .tar.gz archives all work.

3

Receive your threat report

We classify every request in your log against your site's blueprint using the same AI engine that powers Moat AIS protection, then email you a personalised HTML report, ready to open in any browser.

Everything you need to see the threat picture

🎯

Attack volume & severity score

Total requests, attack count, the share of traffic that turned out malicious, and an overall risk rating from Low to Critical.

🌐

Top attacking IPs

Every IP that sent malicious traffic, ranked by volume, alongside their top probe paths and the attack types they favoured.

📊

Traffic classification breakdown

Legitimate visitors, bots, scanners, and attack traffic broken apart and shown as a donut chart with a detailed table underneath.

🔍

Attack type breakdown

SQL injection, path scanning, credential stuffing, vulnerability probing: each category ranked by volume, with real example URLs pulled straight from your log.

24-hour attack timeline

Attack requests broken down by hour, so you can see when your site draws the most attention and how steady that rate is.

🛡

What Moat AIS would have blocked

Every attack that reached your server, with confirmation that Moat AIS would have stopped it automatically before it got there.

Where to find your access log

Your web server keeps a detailed record of every request that hits it. Here's where that record lives.

nginx

/var/log/nginx/access.log /var/log/nginx/access.log.1

Rotated files are numbered. Pass them all through for a fuller picture; anything ending in .gz gets decompressed automatically.

Apache

/var/log/apache2/access.log /var/log/httpd/access_log

The location shifts depending on your distribution. Check /etc/apache2/ or /etc/httpd/ to confirm yours.

cPanel / shared hosting

cPanel → Metrics → Raw Access

Download the last 7 to 30 days. cPanel zips its logs automatically, so just upload the .zip and we'll handle the rest.

Got a .tar.gz or .zip full of logs? Just upload the archive as it is. We'll extract every log file inside and analyse them together for a complete picture.

Common questions

Is this free, no catch?
Yes, and there's no credit card or account required. We offer it because seeing real attack data on your own site makes the case for protection better than we ever could in words. If you decide you want ongoing protection after reading your report, that's when signing up makes sense.
What does "crawling my site" mean?
We visit your website the way a regular user would, following links and discovering pages, and build a blueprint of what legitimate URLs look like from that. It's what lets us tell a real visitor apart from someone probing for vulnerabilities, and since it's entirely passive, your site's performance never feels it.
Is my log data kept confidential?
Your log file gets used only to generate your report, then deleted from our servers right after. We don't store it, share it, or put your traffic data to any other use, and the report itself sits behind a private, token-protected URL that we email straight to you.
How large can my log file be?
We accept files up to 300 MB. Got a large archive of rotated logs? Zip them together and upload that instead; we'll extract and analyse everything inside.
How long does it take?
After you submit your domain, the crawl typically takes 2 to 5 minutes, and you'll get an email with your upload link once it's done. Upload your log and the analysis runs in about 1 to 2 minutes before your report lands in your inbox automatically.
My log is from a site that isn't live yet, will it work?
The crawl needs a live, publicly accessible website to build its blueprint. If yours isn't public yet, get in touch and we'll work out an alternative.

Ready to see your threat report?

Enter your domain and email, and we'll crawl your site, analyse your logs, and send you a security report. No account or credit card needed.

Get my free threat report

Already protected? Sign in to your dashboard →