TTY Logs and the Data it Captures

Executive Summary

A script was created to parse TTY logs generated by actors or bots after they log into a DShield sensor. The logs are collected throughout the day and sent daily to the DShield SIEM for correlation with other data sources, enabling analysis of command activity and potential threats.


Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-10-05T00:15:00+00:00 - Category: threat-intel

Original Description: For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data.

"True silence is the rest of the mind; it is to the spirit what sleep is to the body, nourishment and refreshment."

— William Penn
Source: SANS Internet Storm Center