Skip to main content
INFO Threat Intel #DShield#Threat Intelligence

DShield Honeypot TTY Log Analysis Reveals Common Crontab Attacks

3 min read Runtime Rebel Intel
Primary source: isc.sans.edu

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Analysis of DShield honeypot TTY logs reveals common crontab commands used by over 3,130 unique actors for potential persistence.
  • This intelligence is derived from command logs captured by DShield sensors (honeypots) and correlated within their SIEM.
  • Defenders should prioritize monitoring TTY logs and crontab entries on production systems for similar suspicious activity.

Advertisement

Understanding Attacker TTPs Through TTY Log Analysis

Runtime Rebel examines a recent SANS Internet Storm Center (ISC) diary post detailing an experimental script designed to parse and send TTY (teletypewriter) logs from DShield sensors to a Security Information and Event Management (SIEM) system. This initiative, described by Guy Bruneau, provides valuable insights into the common tactics, techniques, and procedures (TTPs) employed by attackers and automated bots after successfully logging into honeypot systems.

The project underscores the utility of deep log analysis, specifically focusing on the commands executed by unauthorized actors within a controlled environment. By capturing and correlating TTY logs, DShield aims to build a more comprehensive understanding of initial post-compromise activities and persistent threats, offering actionable intelligence for defenders.

DShield Honeypot TTY Log Analysis

The core of the experiment involves a script that processes TTY logs, extracting executed commands and transmitting them daily to the DShield SIEM for correlation. A key finding from this SANS Internet Storm Center analysis highlights widespread attempts at establishing persistence. Using an ES|QL query over a 90-day period, the researchers identified a specific transaction ID (f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8) associated with five similar crontab commands. These commands were executed by over 3,130 different IP addresses (actors), indicating a common and automated approach to maintaining access on compromised systems.

This DShield honeypot TTY log analysis provides concrete examples of how attackers attempt to schedule malicious tasks for recurring execution, such as downloading and running additional payloads or establishing reverse shells. The high volume of unique IP addresses performing these identical crontab commands suggests a widespread, likely automated, campaign targeting internet-facing systems with common vulnerabilities or weak credentials.

Actionable Recommendations for Defenders

For security professionals tasked with safeguarding production environments, the insights gleaned from this honeypot experiment are directly applicable. Understanding how to analyze TTY logs for compromise is a critical capability. Defenders should prioritize the following actions:

  • Implement Comprehensive TTY Log Monitoring: Ensure that TTY logs (or equivalent command history/session logs) are collected, centralized, and monitored for all critical systems. Anomalous command execution or unknown binaries being run warrants immediate investigation.
  • Focus on crontab Integrity: Regularly audit crontab entries on all Linux/Unix-like systems. Look for newly added or modified entries, especially those scheduled to run at unusual intervals or executing suspicious scripts. Tools for monitoring crontab commands for persistence can help automate this review process.
  • Leverage Threat Intelligence: Incorporate intelligence feeds that detail common post-exploitation TTPs, such as those demonstrated by the DShield data, into security operations. This helps refine detection rules and incident response playbooks.
  • Honeypot Deployment: Consider deploying honeypots or deception technologies within your network segments to gain firsthand intelligence on current attack methodologies targeting your specific infrastructure.

Related: Beelzebub Raises $3.4M for AI-Driven Hacker-Trapping Platform, Analyzing Firefox Captive Portal Detection in Network Logs

Advertisement

Advertisement