Threats · InfosecFeed Brief

TTY Logs and the Data it Captures, (Sun, Oct 4th)

Threats

What you need to know

For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. 

Source transparency

This is an InfosecFeed curated brief based on reporting from SANS Internet Storm Center. InfosecFeed does not claim ownership of the original reporting.

Read the original report at SANS Internet Storm Center ↗