TTY Logs and the Data it Captures, (Sun, Oct 4th)

Summary

An experiment was conducted to parse and send TTY logs collected from actors or bots that execute commands after logging into a DShield sensor. These logs are sent daily to the DShield SIEM for correlation with other data.

IFF Assessment

FOE

The article describes how attackers are logging into systems and executing commands, which is a malicious activity that poses a threat to defenders.

Defender Context

This article highlights the importance of monitoring TTY logs, which can provide valuable insights into attacker activity post-compromise. Defenders should ensure they are collecting and analyzing these logs to detect unauthorized command execution and understand attacker methodologies.

Read Full Story →