This project demonstrates how Splunk Enterprise can be used to investigate authentication activity from Linux SSH logs.
The investigation focuses on identifying failed login attempts, successful logins, attacker IP addresses, targeted usernames, and determining whether a brute-force attack resulted in a compromise.
- Import log data into Splunk
- Search indexed events
- Analyze SSH authentication logs
- Extract fields using SPL
- Identify attacker IP addresses
- Identify targeted usernames
- Correlate failed and successful logins
- Produce a security assessment
- Splunk Enterprise
- SPL (Search Processing Language)
- Log Analysis
- SSH Authentication Investigation
- Field Extraction (rex)
- Statistical Analysis (stats)
- Incident Investigation
- Splunk Enterprise
- SPL (Search Processing Language)
- macOS
- Google Chrome
- Over 109,000 events were indexed.
- SSH logs accounted for approximately 40,000 events.
- More than 33,000 failed SSH login attempts were identified.
- Hundreds of external IP addresses attempted authentication.
- Thousands of username guesses were observed.
- Successful logins originated only from three internal IP addresses.
- No evidence showed an external attacker successfully authenticating.
- Evidence
- Screenshots
- Incident Report
- IOC List
The investigation identified a large-scale SSH brute-force attack targeting numerous accounts.
Although successful logins occurred during the same period, they originated from trusted internal IP addresses and legitimate users.
No evidence indicated that an external attacker obtained valid credentials.