Skip to content

TTY logs help correlate attackers’ commands

In an article published by SANS ISC on October 5, 2026, an experiment sends command logs to the DShield SIEM daily after attackers or bots gain access to a sensor.

By Wendelmaques ·

Source: Registros TTY e os dados que capturam (isc.sans.edu). Text prepared with AI from this source.

What happened and what to do

In an article dated October 5, 2026, SANS ISC describes an experiment that analyzes TTY logs of commands run by attackers or bots after they successfully enter a DShield sensor. A script sends these logs to the DShield SIEM at the end of each day for correlation with other available data.

A company could apply this approach by centralizing suspicious-session logs, scheduling their delivery to a SIEM, and correlating commands with other security events. The work could also establish access controls, retention rules, and monitoring to protect these records and make analysis operational.

How the consultancy can help

Wendelmaques can diagnose exposure and log sources, define a collection and correlation architecture, and implement and operate the required pipeline and dashboards, with a scope tailored to the case.

Next step

Send a short description of your environment and monitoring challenge to receive a scoped proposal.

Consulting for your project

Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.

Quoted per project

Request a proposal

Looking for something else?Frequently asked questionsArticlesContact