Most teams treat a successful SSH login as the end of the brute-force story.

This weekend’s SANS Internet Storm Center diary on TTY logs from DShield sensors should kill that habit. After bots and operators guess a password and land a shell, they type. Those keystrokes are the actual cybersecurity event, and a lot of production estates still never capture them.

Monday’s Stormcast will give you headlines.

The TTY pipeline gives you verbs.

The Shell Session Is the Incident

Put a box on the public internet with a guessable login and you will collect TTY. DShield sensors already do this on purpose. Sunday’s ISC diary is an experiment in parsing those post-login transcripts and shipping them at end of day into the DShield SIEM so commands line up with every other sensor event.

That is threat detection with verbs attached.

If a bot lands a shell on your jump host, auth.log will print Accepted password. Your queue may stay quiet if the account is a service ID you expected. The transcript is where you learn they dumped keys, pulled a dropper, or ran a recon one-liner and left.

Honeypots have shown the post-login script for years. uname. wget. crontab. Copy an SSH key. You don’t need Sunday’s exact parser to know production SSH, RDP shadowing, and serial consoles generate the same class of evidence, if you keep it.

Syslog that only stores execve after the fact still helps. A full TTY is better because you see pasted blocks, bot-speed bursts, and the pause before a human runs something stupid. Your detections should care about both rhythms.

Defense in depth that stops at the firewall and the MFA prompt is a door log. Attackers who beat brute-force live inside the session.

Cybersecurity Needs Command Telemetry

Most cyber security programs already drown in auth events. Failed password. Locked account. Geo-impossible VPN. Those records are cheap to store and easy to chart. Command telemetry is fatter, noisier, and more honest.

People treat session recording as a PCI checkbox on a jump box. Run it as incident response fuel instead. When someone asks what they did, you should answer from a file, not from a reconstruction meeting three days later.

Correlate the way DShield is correlating. Source IP, timestamp, username, then the command stream. If your SIEM can join a successful login to a session ID and a first outbound fetch, you have a detection. If it cannot, you have a guestbook.

Threat-protection that never sees process ancestry on a bastion will miss living-off-the-land inside an allowed SSH flow.

Packet filters do not parse bash.

Harden the account plane at the same time. Disable password SSH where you can. Put interactive Unix and Windows admin behind a recorded broker. Kill shared root. Rotate keys when a transcript shows unexpected use, even if EDR stayed quiet.

Shared credentials make every transcript ambiguous.

Vendor tools that score “risky login” and stop there will train your SOC to close the ticket when MFA succeeds. Keep the case open until the session ends and the command list is in the file.

Capture Keystrokes Before the Next Login

Do this this week on the hosts that already matter: jump boxes, hypervisor consoles, firewall CLI users, Kubernetes admin bastions, and anything that still offers password SSH to the internet.

You already know which boxes mint admin sessions. Start there.

If you can’t replay last Tuesday’s root session, you are guessing.

  • Immediate: turn on native session recording or TTY auditing for interactive admin, and prove you can replay a test session from your SIEM or log archive.
  • Immediate: tag every successful interactive login with a session ID and alert when that session has no command telemetry within a few minutes.
  • Immediate: autoban repeat brute-force sources at the host or edge with ipban-style blocks. IPBan Pro covers that job on Windows jump hosts if that is your admin OS. Still record the session if one guess succeeds.
  • Ongoing: once a day, sample transcripts the way DShield ships TTY at end of day. Hunt wget, curl, python -c, ssh-keygen, crontab, and unexpected scp. Feed hits into incident response the same shift.
  • Ongoing: security hardening on the same boxes, including key-only SSH, no shared root, outbound default-deny from bastions, and a written rule that a live shell on an admin host is a P1 until the transcript says otherwise.

A recorded miss still beats an empty auth success.

Start with one bastion. Prove replay. Then expand until every interactive admin path leaves a transcript your SIEM can join to the login that opened it.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.