SANS ISC Shares DShield Honeypot TTY Analysis
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
SANS ISC researcher used ES|QL to correlate TTY log hashes from a Cowrie honeypot, finding over 3,130 IPs running identical crontab commands.
This SANS Internet Storm Center diary describes a methodology for analyzing TTY session logs captured by a DShield honeypot sensor (Cowrie-based). The author built a script that parses TTY logs from post-login actor/bot activity and forwards them daily to a DShield SIEM (built on Elastic) for correlation. Using an ES|QL query, the author grouped sessions by event.hash to identify repeated command patterns across different source IPs.
The highlighted example shows a single transaction/hash corresponding to a set of near-identical crontab commands executed by more than 3,130 distinct IP addresses over a 90-day period, indicating widespread automated/bot-driven scanning or exploitation attempts using a common toolkit or script template. A table of the top 10 source IPs and their associated ASNs is provided as illustrative indicators from this dataset. No specific malware family, exploit, or vulnerability is named; the piece is primarily a methodology showcase for honeypot telemetry analysis and correlation tooling (scripts and SIEM config linked via GitHub) rather than a disclosure of a new threat or campaign.
For defenders, this serves mainly as an example of how to use ES|QL and honeypot TTY data to cluster bot activity by behavioral signature (command hash) rather than by IP alone, which can help identify related infrastructure or campaigns despite IP churn. The specific IOCs listed are honeypot-observed source IPs engaging in generic crontab-based persistence/automation attempts, consistent with routine opportunistic scanning rather than a targeted or novel attack.
Detection guidance
Piped Input Installed Into Crontab via Shell
Detects a shell command line that pipes generated content (echo/cat/curl/wget output) straight into crontab, a common pattern for automated bot cron persistence. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Piped Input Installed Into Crontab via Shell
description: Detects Linux shell command lines that pipe generated content into crontab
(for example crontab -l | { cat; echo entry; } | crontab -). Automated bots use
this pattern to add cron persistence without editing files. Generalises on the pipe-into-crontab
pattern, not on any specific entry or payload.
tags:
- attack.persistence
- attack.execution
- attack.t1053.003
logsource:
category: process_creation
product: linux
detection:
selection_shell:
Image|endswith:
- /sh
- /bash
- /dash
selection_pipe:
CommandLine|contains:
- '| crontab -'
- '|crontab -'
- '| crontab /dev/stdin'
filter_benign:
CommandLine|contains:
- crontab -l | crontab -u
condition: selection_shell and selection_pipe and not filter_benign
falsepositives:
- Configuration management or provisioning scripts that append entries to a crontab
through a pipe
- Administrators manually editing crontab through a one-liner
level: medium
id: 3d7ad9fe-bfdb-5dae-b1f5-a739b8240b4e
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33396
Crontab Cleared or Replaced Together With Download Utility
Detects a single shell command line that manipulates crontab (remove, or install from stdin) and also uses curl/wget/tftp, as seen in bot-driven cron persistence. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Crontab Cleared or Replaced Together With Download Utility
description: Detects Linux shell command lines that combine a crontab modification
(crontab -r or crontab -) with a download tool such as curl, wget or tftp. This
is typical of opportunistic bot scripts that reset the crontab and install a downloader
job. Matches on the combination of behaviours, not on any URL or filename.
tags:
- attack.persistence
- attack.execution
- attack.t1053.003
logsource:
category: process_creation
product: linux
detection:
selection_shell:
Image|endswith:
- /sh
- /bash
- /dash
selection_crontab:
CommandLine|contains:
- crontab -r
- crontab -
- crontab /dev/stdin
selection_download:
CommandLine|contains:
- 'curl '
- 'wget '
- 'tftp '
condition: selection_shell and selection_crontab and selection_download
falsepositives:
- Provisioning or bootstrap scripts that download a file and install a scheduled job
in one command
- Admin one-liners that deploy a cron-based update checker
level: medium
id: 6bd00acb-86f3-51b0-a795-31e538bb93c7
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33396
3 more detections for this report are in the app — the rules that match its indicators, plus every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. Three days of it free, no card.
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://isc.sans.edu/diary/rss/33396
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,692 reports from 151 sources, 492 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs