Back to all posts
Day 73Tuesday, April 14, 20262 min read

Detecting SSH Brute Force Attacks Using auth.log

cybersecuritylinuxlogssshlearningprocess
View original post

๐Ÿ”„ Topic

Analyzing Linux authentication logs to identify brute-force login attempts.


๐ŸŽฏ Goal

Learn how to detect SSH brute-force attacks by analyzing real log data.


๐Ÿ›  What I Did

Worked with /var/log/auth.log and analyzed failed SSH login attempts.

Used command-line tools:

grep "Failed password" /var/log/auth.log

Then extracted attacker IPs:

grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}'

Then counted attempts:

grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr

๐Ÿ”— Key Cybersecurity Connections

SSH brute force is one of the most common attack types:

  • attackers try many passwords
  • target exposed SSH services
  • often automated

๐Ÿ” Investigation Questions

  • Which IP is generating the most failed attempts?
  • Are multiple usernames targeted?
  • Is the attack distributed or from a single source?

๐Ÿšจ Detection Opportunities

  • multiple failed login attempts from same IP
  • rapid repeated authentication failures
  • login attempts across many usernames

๐Ÿงญ MITRE ATT&CK Techniques

  • T1110 โ€” Brute Force

โš  Challenges

Understanding log structure and extracting the correct field.


๐Ÿ“š What I Learned

  • logs contain raw evidence
  • aggregation reveals patterns
  • simple tools can produce powerful insights
  • field extraction needs to be verified against the actual log format
  • a useful detection starts with a clear question, not with a complicated command

โžก Next Steps

  • detect successful login after failures
  • correlate IP with threat intelligence

๐Ÿง  Reflection

This was the first time logs felt like actual evidence, not just text.

The strongest lesson was that a simple pipeline can become a real investigation when each step is explainable. I want future detections to have that same quality: transparent enough to defend, practical enough to use.


๐Ÿงฉ Lessons Learned

What worked

Using pipelines to transform data.

What broke

Initial confusion about field positions.

Why it broke

Log formats are not always intuitive.

Fix / takeaway

Break logs step by step.


๐Ÿ“ˆ Skill Progression Context

This is a core SOC skill: turning raw logs into actionable intelligence.


๐Ÿ˜„ TL;DR

One failed login = noise
1000 failed logins = someone knocking very loudly