📅 Day 73 — Detecting SSH Brute Force Attacks Using auth.log
🔄 Topic
Analyzing Linux authentication logs to identify brute-force login attempts.
🎯 Goal
Learn how to detect SSH brute-force attacks by analyzing real log data.
🛠 What I Did
Worked with /var/log/auth.log and analyzed failed SSH login attempts.
Used command-line tools:
grep "Failed password" /var/log/auth.log
Then extracted attacker IPs:
grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}'
Then counted attempts:
grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr
🔗 Key Cybersecurity Connections
SSH brute force is one of the most common attack types:
- attackers try many passwords
- target exposed SSH services
- often automated
🔍 Investigation Questions
- Which IP is generating the most failed attempts?
- Are multiple usernames targeted?
- Is the attack distributed or from a single source?
🚨 Detection Opportunities
- multiple failed login attempts from same IP
- rapid repeated authentication failures
- login attempts across many usernames
🧭 MITRE ATT&CK Techniques
- T1110 — Brute Force
⚠ Challenges
Understanding log structure and extracting the correct field.
📚 What I Learned
- logs contain raw evidence
- aggregation reveals patterns
- simple tools can produce powerful insights
- field extraction needs to be verified against the actual log format
- a useful detection starts with a clear question, not with a complicated command
➡ Next Steps
- detect successful login after failures
- correlate IP with threat intelligence
🧠 Reflection
This was the first time logs felt like actual evidence, not just text.
The strongest lesson was that a simple pipeline can become a real investigation when each step is explainable. I want future detections to have that same quality: transparent enough to defend, practical enough to use.
🧩 Lessons Learned
What worked
Using pipelines to transform data.
What broke
Initial confusion about field positions.
Why it broke
Log formats are not always intuitive.
Fix / takeaway
Break logs step by step.
📈 Skill Progression Context
This is a core SOC skill: turning raw logs into actionable intelligence.
😄 TL;DR
One failed login = noise
1000 failed logins = someone knocking very loudly
