🔄 Topic

Analyzing Linux authentication logs to identify brute-force login attempts.


🎯 Goal

Learn how to detect SSH brute-force attacks by analyzing real log data.


🛠 What I Did

Worked with /var/log/auth.log and analyzed failed SSH login attempts.

Used command-line tools:

grep "Failed password" /var/log/auth.log

Then extracted attacker IPs:

grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}'

Then counted attempts:

grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr

🔗 Key Cybersecurity Connections

SSH brute force is one of the most common attack types:

  • attackers try many passwords
  • target exposed SSH services
  • often automated

🔍 Investigation Questions

  • Which IP is generating the most failed attempts?
  • Are multiple usernames targeted?
  • Is the attack distributed or from a single source?

🚨 Detection Opportunities

  • multiple failed login attempts from same IP
  • rapid repeated authentication failures
  • login attempts across many usernames

🧭 MITRE ATT&CK Techniques

  • T1110 — Brute Force

⚠ Challenges

Understanding log structure and extracting the correct field.


📚 What I Learned

  • logs contain raw evidence
  • aggregation reveals patterns
  • simple tools can produce powerful insights
  • field extraction needs to be verified against the actual log format
  • a useful detection starts with a clear question, not with a complicated command

➡ Next Steps

  • detect successful login after failures
  • correlate IP with threat intelligence

🧠 Reflection

This was the first time logs felt like actual evidence, not just text.

The strongest lesson was that a simple pipeline can become a real investigation when each step is explainable. I want future detections to have that same quality: transparent enough to defend, practical enough to use.


🧩 Lessons Learned

What worked

Using pipelines to transform data.

What broke

Initial confusion about field positions.

Why it broke

Log formats are not always intuitive.

Fix / takeaway

Break logs step by step.


📈 Skill Progression Context

This is a core SOC skill: turning raw logs into actionable intelligence.


😄 TL;DR

One failed login = noise
1000 failed logins = someone knocking very loudly