Understanding Attacker TTPs Through TTY Log Analysis
Runtime Rebel examines a recent SANS Internet Storm Center (ISC) diary post detailing an experimental script designed to parse and send TTY (teletypewriter) logs from DShield sensors to a Security Information and Event Management (SIEM) system. This initiative, described by Guy Bruneau, provides valuable insights into the common tactics, techniques, and procedures (TTPs) employed by attackers and automated bots after successfully logging into honeypot systems.
The project underscores the utility of deep log analysis, specifically focusing on the commands executed by unauthorized actors within a controlled environment. By capturing and correlating TTY logs, DShield aims to build a more comprehensive understanding of initial post-compromise activities and persistent threats, offering actionable intelligence for defenders.
DShield Honeypot TTY Log Analysis
The core of the experiment involves a script that processes TTY logs, extracting executed commands and transmitting them daily to the DShield SIEM for correlation. A key finding from this SANS Internet Storm Center analysis highlights widespread attempts at establishing persistence. Using an ES|QL query over a 90-day period, the researchers identified a specific transaction ID (f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8) associated with five similar crontab commands. These commands were executed by over 3,130 different IP addresses (actors), indicating a common and automated approach to maintaining access on compromised systems.
This DShield honeypot TTY log analysis provides concrete examples of how attackers attempt to schedule malicious tasks for recurring execution, such as downloading and running additional payloads or establishing reverse shells. The high volume of unique IP addresses performing these identical crontab commands suggests a widespread, likely automated, campaign targeting internet-facing systems with common vulnerabilities or weak credentials.
Actionable Recommendations for Defenders
For security professionals tasked with safeguarding production environments, the insights gleaned from this honeypot experiment are directly applicable. Understanding how to analyze TTY logs for compromise is a critical capability. Defenders should prioritize the following actions:
- Implement Comprehensive TTY Log Monitoring: Ensure that TTY logs (or equivalent command history/session logs) are collected, centralized, and monitored for all critical systems. Anomalous command execution or unknown binaries being run warrants immediate investigation.
- Focus on
crontabIntegrity: Regularly auditcrontabentries on all Linux/Unix-like systems. Look for newly added or modified entries, especially those scheduled to run at unusual intervals or executing suspicious scripts. Tools formonitoring crontab commands for persistencecan help automate this review process. - Leverage Threat Intelligence: Incorporate intelligence feeds that detail common post-exploitation TTPs, such as those demonstrated by the DShield data, into security operations. This helps refine detection rules and incident response playbooks.
- Honeypot Deployment: Consider deploying honeypots or deception technologies within your network segments to gain firsthand intelligence on current attack methodologies targeting your specific infrastructure.
Related: Beelzebub Raises $3.4M for AI-Driven Hacker-Trapping Platform, Analyzing Firefox Captive Portal Detection in Network Logs