Detecting SSH Brute Force Attacks Using auth.log
๐ Topic
Analyzing Linux authentication logs to identify brute-force login attempts.
๐ฏ Goal
Learn how to detect SSH brute-force attacks by analyzing real log data.
๐ What I Did
Worked with /var/log/auth.log and analyzed failed SSH login attempts.
Used command-line tools:
grep "Failed password" /var/log/auth.log
Then extracted attacker IPs:
grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}'
Then counted attempts:
grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr
๐ Key Cybersecurity Connections
SSH brute force is one of the most common attack types:
- attackers try many passwords
- target exposed SSH services
- often automated
๐ Investigation Questions
- Which IP is generating the most failed attempts?
- Are multiple usernames targeted?
- Is the attack distributed or from a single source?
๐จ Detection Opportunities
- multiple failed login attempts from same IP
- rapid repeated authentication failures
- login attempts across many usernames
๐งญ MITRE ATT&CK Techniques
- T1110 โ Brute Force
โ Challenges
Understanding log structure and extracting the correct field.
๐ What I Learned
- logs contain raw evidence
- aggregation reveals patterns
- simple tools can produce powerful insights
- field extraction needs to be verified against the actual log format
- a useful detection starts with a clear question, not with a complicated command
โก Next Steps
- detect successful login after failures
- correlate IP with threat intelligence
๐ง Reflection
This was the first time logs felt like actual evidence, not just text.
The strongest lesson was that a simple pipeline can become a real investigation when each step is explainable. I want future detections to have that same quality: transparent enough to defend, practical enough to use.
๐งฉ Lessons Learned
What worked
Using pipelines to transform data.
What broke
Initial confusion about field positions.
Why it broke
Log formats are not always intuitive.
Fix / takeaway
Break logs step by step.
๐ Skill Progression Context
This is a core SOC skill: turning raw logs into actionable intelligence.
๐ TL;DR
One failed login = noise
1000 failed logins = someone knocking very loudly