CYBERSECURITYTRACKER
TRACKING
Permanent story citation

TTY Logs and the Data it Captures

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9333

As cited

Copy frozen at (site build).

threat intel

TTY Logs and the Data it Captures

A researcher analyzed TTY logs from a DShield sensor honeypot to track command execution by unauthorized actors over a 90-day period. The data revealed that over 3,130 distinct IP addresses executed identical crontab commands, with the top attack sources identified by IP and autonomous system number (ASN).

Why it matters: Practitioners monitoring DShield and honeypot data gain insight into attacker command patterns and geographic distribution; the identified IPs and ASNs can inform threat intelligence feeds and network blocking decisions.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary