TTY Logs and the Data it Captures

A SANS Internet Storm Center experiment parses TTY logs capturing the commands attackers and bots run after successfully logging into a DShield honeypot sensor. The logs are sent daily to the DShield SIEM for correlation with other collected data. The diary post describes what the captured session data reveals about intruder activity.

Source: isc.sans.edu

Curated Permalink