I've been scouring google for a decent IIS log analyzer that will help me monitor for simple hacking attempts.
Things like SQL Injection, or integer overloading, etc.
All of the log analyzers I have found are good for showing hits, visitors, etc - which is useful information, but nothing so far has been able to identify that there was an attempted apparent malicious attempt made on our website.
Can anyone recommend one? Commercial or free, doesn't matter.
Note, I'm NOT looking for a URL scanner, ISAPI filter, etc. for preventing these types of attacks - our code has been safeguarded - I'm merely interested in identifying ATTEMPTED threats so we can pass their IPs along to the appropriate authorities.
Right now this involves a manual scan of the logfile every day - which is rather tedious.