DShield Parses TTY Command Logs from Compromised Sensors for Daily SIEM Correlation
What Happened — A SANS Internet Storm Center diary entry describes a script that extracts TTY session logs from actors or bots that successfully log into DShield sensors. The parsed logs are shipped each night to the DShield SIEM for correlation with other telemetry.
Why It Matters for Trust & Control Assurance
- Continuous collection of command‑line activity creates a defensible audit trail, satisfying the control objective of comprehensive logging and monitoring.
- Correlating TTY logs with broader sensor data enables real‑time detection of credential misuse and malicious automation, a core evidence source for continuous control‑assurance programs.
- The practice demonstrates due‑diligence in evidence collection, which can be presented during audits or third‑party assessments.
Who Is Affected — Organizations that run internet‑facing sensors, honeypots, or any environment where privileged access to Linux‑style terminals is possible (e.g., cloud‑infrastructure providers, security‑operations teams, research labs).
Recommended Actions
- Enable full TTY/command‑line logging on all privileged and exposed endpoints.
- Centralize logs in a tamper‑evident SIEM and retain them per regulatory or policy requirements.
- Map the logging process to the control objective of “audit logging and monitoring” and collect evidence for audit readiness.
Technical Notes — The script captures raw TTY output, including typed commands and responses, and forwards the data via a daily batch job. No specific CVE or vulnerability is disclosed; the focus is on the value of the log data for threat detection. Source: SANS ISC Diary