TTY logs help correlate attackers’ commands
In an article published by SANS ISC on October 5, 2026, an experiment sends command logs to the DShield SIEM daily after attackers or bots gain access to a sensor.
Source: Registros TTY e os dados que capturam (isc.sans.edu). Text prepared with AI from this source.
What happened and what to do
In an article dated October 5, 2026, SANS ISC describes an experiment that analyzes TTY logs of commands run by attackers or bots after they successfully enter a DShield sensor. A script sends these logs to the DShield SIEM at the end of each day for correlation with other available data.
A company could apply this approach by centralizing suspicious-session logs, scheduling their delivery to a SIEM, and correlating commands with other security events. The work could also establish access controls, retention rules, and monitoring to protect these records and make analysis operational.
How the consultancy can help
Wendelmaques can diagnose exposure and log sources, define a collection and correlation architecture, and implement and operate the required pipeline and dashboards, with a scope tailored to the case.
Next step
Send a short description of your environment and monitoring challenge to receive a scoped proposal.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal