Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Splunk Detection Lab

Overview

This project demonstrates how Splunk Enterprise can be used to investigate authentication activity from Linux SSH logs.

The investigation focuses on identifying failed login attempts, successful logins, attacker IP addresses, targeted usernames, and determining whether a brute-force attack resulted in a compromise.


Objectives

  • Import log data into Splunk
  • Search indexed events
  • Analyze SSH authentication logs
  • Extract fields using SPL
  • Identify attacker IP addresses
  • Identify targeted usernames
  • Correlate failed and successful logins
  • Produce a security assessment

Skills Demonstrated

  • Splunk Enterprise
  • SPL (Search Processing Language)
  • Log Analysis
  • SSH Authentication Investigation
  • Field Extraction (rex)
  • Statistical Analysis (stats)
  • Incident Investigation

Tools Used

  • Splunk Enterprise
  • SPL (Search Processing Language)
  • macOS
  • Google Chrome

Key Findings

  • Over 109,000 events were indexed.
  • SSH logs accounted for approximately 40,000 events.
  • More than 33,000 failed SSH login attempts were identified.
  • Hundreds of external IP addresses attempted authentication.
  • Thousands of username guesses were observed.
  • Successful logins originated only from three internal IP addresses.
  • No evidence showed an external attacker successfully authenticating.

Repository Structure

  • Evidence
  • Screenshots
  • Incident Report
  • IOC List

Conclusion

The investigation identified a large-scale SSH brute-force attack targeting numerous accounts.

Although successful logins occurred during the same period, they originated from trusted internal IP addresses and legitimate users.

No evidence indicated that an external attacker obtained valid credentials.

About

Hands-on Splunk Enterprise investigation using SPL to detect SSH brute-force attacks, correlate authentication events, analyze login activity, and produce professional SOC incident documentation.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors