# SANS ISC Shares DShield Honeypot TTY Analysis

Published: 2026-10-05 · Severity: routine
Canonical: https://vorant.io/reports/00dde4a9-6da6-57bd-880c-8ff9d34e4a6f/sans-isc-shares-dshield-honeypot-tty-analysis

> SANS ISC researcher used ES|QL to correlate TTY log hashes from a Cowrie honeypot, finding over 3,130 IPs running identical crontab commands.

This SANS Internet Storm Center diary describes a methodology for analyzing TTY session logs captured by a DShield honeypot sensor (Cowrie-based). The author built a script that parses TTY logs from post-login actor/bot activity and forwards them daily to a DShield SIEM (built on Elastic) for correlation. Using an ES|QL query, the author grouped sessions by event.hash to identify repeated command patterns across different source IPs.

The highlighted example shows a single transaction/hash corresponding to a set of near-identical crontab commands executed by more than 3,130 distinct IP addresses over a 90-day period, indicating widespread automated/bot-driven scanning or exploitation attempts using a common toolkit or script template. A table of the top 10 source IPs and their associated ASNs is provided as illustrative indicators from this dataset. No specific malware family, exploit, or vulnerability is named; the piece is primarily a methodology showcase for honeypot telemetry analysis and correlation tooling (scripts and SIEM config linked via GitHub) rather than a disclosure of a new threat or campaign.

For defenders, this serves mainly as an example of how to use ES|QL and honeypot TTY data to cluster bot activity by behavioral signature (command hash) rather than by IP alone, which can help identify related infrastructure or campaigns despite IP churn. The specific IOCs listed are honeypot-observed source IPs engaging in generic crontab-based persistence/automation attempts, consistent with routine opportunistic scanning rather than a targeted or novel attack.

## Detection guidance (public sample)

### Piped Input Installed Into Crontab via Shell

ATT&CK: T1053.003

Detects a shell command line that pipes generated content (echo/cat/curl/wget output) straight into crontab, a common pattern for automated bot cron persistence. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Piped Input Installed Into Crontab via Shell
description: Detects Linux shell command lines that pipe generated content into crontab
  (for example crontab -l | { cat; echo entry; } | crontab -). Automated bots use
  this pattern to add cron persistence without editing files. Generalises on the pipe-into-crontab
  pattern, not on any specific entry or payload.
tags:
- attack.persistence
- attack.execution
- attack.t1053.003
logsource:
  category: process_creation
  product: linux
detection:
  selection_shell:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_pipe:
    CommandLine|contains:
    - '| crontab -'
    - '|crontab -'
    - '| crontab /dev/stdin'
  filter_benign:
    CommandLine|contains:
    - crontab -l |  crontab -u
  condition: selection_shell and selection_pipe and not filter_benign
falsepositives:
- Configuration management or provisioning scripts that append entries to a crontab
  through a pipe
- Administrators manually editing crontab through a one-liner
level: medium
id: 3d7ad9fe-bfdb-5dae-b1f5-a739b8240b4e
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33396
```

### Crontab Cleared or Replaced Together With Download Utility

ATT&CK: T1053.003

Detects a single shell command line that manipulates crontab (remove, or install from stdin) and also uses curl/wget/tftp, as seen in bot-driven cron persistence. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Crontab Cleared or Replaced Together With Download Utility
description: Detects Linux shell command lines that combine a crontab modification
  (crontab -r or crontab -) with a download tool such as curl, wget or tftp. This
  is typical of opportunistic bot scripts that reset the crontab and install a downloader
  job. Matches on the combination of behaviours, not on any URL or filename.
tags:
- attack.persistence
- attack.execution
- attack.t1053.003
logsource:
  category: process_creation
  product: linux
detection:
  selection_shell:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_crontab:
    CommandLine|contains:
    - crontab -r
    - crontab -
    - crontab /dev/stdin
  selection_download:
    CommandLine|contains:
    - 'curl '
    - 'wget '
    - 'tftp '
  condition: selection_shell and selection_crontab and selection_download
falsepositives:
- Provisioning or bootstrap scripts that download a file and install a scheduled job
  in one command
- Admin one-liners that deploy a cron-based update checker
level: medium
id: 6bd00acb-86f3-51b0-a795-31e538bb93c7
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33396
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

3 more detections for this report are in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://isc.sans.edu/diary/rss/33396

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/00dde4a9-6da6-57bd-880c-8ff9d34e4a6f/sans-isc-shares-dshield-honeypot-tty-analysis.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
