Skip to content

TTY logs reveal commands after intrusions

Published on October 5, 2026, the account describes an experiment that sends DShield SIEM daily TTY logs of commands run after attackers or bots successfully access a sensor.

By Wendelmaques ·

Source: Registros TTY e os dados que capturam (isc.sans.edu). Text prepared with AI from this source.

What happened and what to do

On October 5, 2026, a SANS ISC account described an experiment using a script to analyze TTY logs of commands run by attackers or bots after they successfully enter a DShield sensor. The logs are sent to DShield SIEM at the end of each day for correlation with other data. The account does not report correlation results. Consult the SANS ISC diary entry under identifier 33396, and verify the scope and details in the original text; the feed content is presented as an automatic translation.

For a company, the practical response is to assess whether terminal and sensor logs are collected, retained, and correlated securely and usefully. A daily pipeline could normalize records, enforce access controls, apply a retention policy, and alert on suspicious activity, with a dashboard to track commands and incidents. The right design depends on available data sources and security and operational requirements.

How the consultancy can help

Wendelmaques can assess log-collection coverage and risks, define an implementation scope, and deliver the required pipeline, integrations, access controls, and dashboards. It can also propose operating and maintaining the solution to fit the company’s needs.

Next step

Send a short description of your company’s sensors, logs, and monitoring needs to receive a scoped proposal.

Consulting for your project

Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.

Quoted per project

Request a proposal