TTY Logs and the Data it Captures, (Sun, Oct 4th)

A Recent Experiment Reveals the Power of TTY Logs in Uncovering Malicious Activity

In a fascinating experiment, cybersecurity researcher Guy Bruneau has shed light on the importance of Terminal Type (TTY) logs in detecting and analyzing malicious activity. By collecting and parsing these logs from various actors and bots, Bruneau’s script was able to identify patterns and connections that would have gone unnoticed otherwise.

For those who may not be familiar with TTY logs, they are records of commands executed on a system after an actor or bot has successfully logged in. These logs can provide valuable insights into the behavior of malicious actors, including their command history, login attempts, and interactions with the system. In this experiment, Bruneau’s script collected these logs daily from the DShield sensor, a network intrusion detection system, and sent them to the DShield SIEM (Security Information and Event Management) system for analysis.

The results of the experiment were striking. By using Elasticsearch Query Language (ESQL), Bruneau was able to query the TTY logs and identify a specific transaction ID that had been used by over 3,130 different actors (IPs) in the past 90 days. This transaction ID corresponded to a list of similar crontab commands that were executed by these malicious actors. Furthermore, Bruneau’s script was able to decode event hashes from these logs and send them to the DShield SIEM for further analysis.

The implications of this experiment are significant. TTY logs can provide a treasure trove of information about malicious activity, including command history, login attempts, and interactions with the system. By analyzing these logs, security professionals can gain valuable insights into the behavior of attackers and identify patterns that may not be apparent otherwise.

One of the key takeaways from this experiment is the importance of collecting and analyzing TTY logs in real-time. By doing so, organizations can quickly detect and respond to malicious activity, reducing the risk of data breaches and other cyber threats. Additionally, Bruneau’s script demonstrates the power of Elasticsearch and ESQL in querying and analyzing these logs.

In practical terms, this experiment highlights the importance of monitoring TTY logs as part of an organization’s overall cybersecurity strategy. This can be achieved by implementing a network intrusion detection system like DShield, which collects and analyzes logs from various sources, including TTY logs. By doing so, organizations can stay ahead of malicious actors and protect their networks from cyber threats.

In conclusion, Bruneau’s experiment demonstrates the value of TTY logs in uncovering malicious activity and provides valuable insights into the behavior of attackers. As cybersecurity professionals, it is essential to prioritize the collection and analysis of these logs as part of our overall defense strategy. By doing so, we can better protect our networks from cyber threats and stay one step ahead of malicious actors.


Source: SANS ISC — 2026-10-05