As cited
Copy frozen at (site build).
threat intel
TTY Logs and the Data it Captures
A researcher analyzed TTY logs from a DShield sensor honeypot to track command execution by unauthorized actors over a 90-day period. The data revealed that over 3,130 distinct IP addresses executed identical crontab commands, with the top attack sources identified by IP and autonomous system number (ASN).
Why it matters: Practitioners monitoring DShield and honeypot data gain insight into attacker command patterns and geographic distribution; the identified IPs and ASNs can inform threat intelligence feeds and network blocking decisions.
- Source published
- First seen by Cybersecurity Tracker