See the attacks your site is already taking.

Spectry inspects what visitors submit through your forms, search boxes and query parameters, and raises an alert the moment one carries an attack payload. Every alert records the page, the parameter and the severity, so you hear about it from your own dashboard.

The detected attacks view in Spectry, with a daily attack chart above a table of attack type, affected URL, parameter and status

Detected, alerted and explained.

Detected

Every value a visitor sends you.

Query strings, form fields and request bodies are checked against known attack patterns as they arrive. A scripting payload hidden in a search parameter is recognized on the spot, with the page and the time it was seen. There is nothing extra to deploy.

Alerted

Told at the time, not at the audit.

A match raises an alert straight away, carrying a severity so the dangerous ones stand out. An automated scanner poking at a login form is not the same as an injection payload reaching a field that reads from your database.

Explained

The payload, not just the label.

Every attack is stored with the request that carried it, so you can see what was attempted rather than a category name. The affected page tells you where to harden, and the pattern tells you what to validate.


What gets flagged.

Cross-site scripting payloads in query parameters
SQL injection patterns in login, search and form fields
OS command injection and path traversal in submitted values
LDAP filter manipulation in lookup and sign-in inputs
NoSQL operator injection inside JSON request bodies
Template injection in any user-supplied string

Why teams watch this page.

Probing comes before the breach

Serious attempts are usually preceded by weeks of automated scanning. Seeing that traffic gives you the chance to fix the input handling before somebody finds the field that works.

Security without a security team

Most sites have no one whose job is reading logs for attacks. An alert that names the page, the parameter and the severity is enough for a small team to act sensibly.

Evidence when it matters

If something does go wrong, a timestamped record of which parameter carried what payload against which page is the difference between an investigation and a guess.

One tool, one script

Detection rides along with the analytics you already installed. No separate agent, no extra vendor, and no additional data leaving the EU.


We protect your data.

GDPR compliant
EU hosted
PII masking
Consent Management

Find out what is being tried.

Detection starts with the same install as everything else in Spectry. No credit card needed, and early-access members earn exclusive rewards.