For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. The following ES|QL query provides a summary of all contab commands matching a TTYLog hash performed by different actors while logged in the sensor over a 90 day period.
TTY Logs and the Data it Captures, (Sun, Oct 4th)
About this summary. This is a short, independently written summary of an article first published by SANS Internet Storm Center. Cyber Security News did not report or verify the underlying story. Read the original: https://isc.sans.edu/diary/rss/33396

Source attribution: headline and facts are from SANS Internet Storm Center (isc.sans.edu). Summary method: excerpt of the source description. See our source attribution policy.


