<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #DShield</title><description>Cybersecurity articles tagged #DShield on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>DShield Honeypot TTY Log Analysis Reveals Common Crontab Attacks</title><link>https://runtimerebel.com/blog/dshield-honeypot-tty-log-analysis-reveals-common-crontab-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-honeypot-tty-log-analysis-reveals-common-crontab-attacks</guid><description>Runtime Rebel analyzes SANS ISC&apos;s report on TTY log collection from DShield honeypots, revealing common crontab commands executed by over 3,130 unique actors.</description><pubDate>Mon, 05 Oct 2026 03:03:17 GMT</pubDate><category>DShield</category><category>Honeypots</category><category>Log Analysis</category><category>Threat Intelligence</category><category>TTY Logs</category></item><item><title>DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging</title><link>https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</guid><description>SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.</description><pubDate>Wed, 15 Jul 2026 10:11:13 GMT</pubDate><category>DShield</category><category>SIEM</category><category>ELK Stack</category><category>SANS ISC</category><category>Honeypot</category><category>Log Analysis</category></item><item><title>DShield Sensor Analysis: A Year of Observed Threat Upload Trends</title><link>https://runtimerebel.com/blog/dshield-sensor-analysis-a-year-of-observed-threat-upload-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-sensor-analysis-a-year-of-observed-threat-upload-trends</guid><description>Runtime Rebel analyzes a year of file uploads to DShield sensors, revealing peak threat activity from December 2025 to February 2026 and subsequent decline.</description><pubDate>Thu, 28 May 2026 20:55:02 GMT</pubDate><category>DShield</category><category>Threat Intelligence</category><category>Sensor Data</category><category>Threat Trends</category><category>Kibana</category><category>ESQL</category></item><item><title>DShield Honeypot Updates: Ensuring Timely Threat Data Collection</title><link>https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</guid><description>SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.</description><pubDate>Mon, 04 May 2026 16:47:53 GMT</pubDate><category>DShield</category><category>Honeypot</category><category>SANS ISC</category><category>Threat Intelligence</category><category>Security Updates</category></item><item><title>Emerging Reconnaissance: Attackers Actively Probe AI Models</title><link>https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</guid><description>DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.</description><pubDate>Wed, 15 Apr 2026 00:46:56 GMT</pubDate><category>AI Models</category><category>Scanning</category><category>Reconnaissance</category><category>Threat Intelligence</category><category>DShield</category><category>Hugging Face</category><category>Claude</category><category>OpenClaw</category></item><item><title>Cowrie Honeypot Analysis: Detecting Automated Session Disconnects</title><link>https://runtimerebel.com/blog/cowrie-honeypot-analysis-detecting-automated-session-disconnects</link><guid isPermaLink="true">https://runtimerebel.com/blog/cowrie-honeypot-analysis-detecting-automated-session-disconnects</guid><description>Analyze DShield Cowrie honeypot data to distinguish between automated bot traffic and manual actor activity through session duration and exit commands.</description><pubDate>Mon, 30 Mar 2026 00:41:28 GMT</pubDate><category>Cowrie</category><category>DShield</category><category>Honeypots</category><category>Ssh Security</category><category>Telnet Traffic</category></item><item><title>Analysis of &apos;iranbot&apos; Message in Cowrie Honeypot Logs</title><link>https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</guid><description>A peculiar &apos;iranbot_was_here&apos; message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.</description><pubDate>Thu, 19 Mar 2026 04:43:57 GMT</pubDate><category>Cowrie</category><category>Honeypot</category><category>Telnet</category><category>Reconnaissance</category><category>Iranbot</category><category>DShield</category><category>Logging</category></item><item><title>Optimizing Honeypot Log Analysis Using AI and LLM Orchestration</title><link>https://runtimerebel.com/blog/optimizing-honeypot-log-analysis-using-ai-and-llm-orchestration</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-honeypot-log-analysis-using-ai-and-llm-orchestration</guid><description>An analysis of how AI-assisted log processing reduces noise in DShield and Cowrie honeypot data, enabling analysts to identify sophisticated threat patterns.</description><pubDate>Thu, 26 Feb 2026 04:39:18 GMT</pubDate><category>AI ML</category><category>Honeypots</category><category>Cowrie</category><category>DShield</category><category>Log Analysis</category><category>Threat Hunting</category></item></channel></rss>