Skip to content
Rota Nacional

Cyber ·

TTY logs from DShield sensors sent daily to a SIEM

An experiment reported by the SANS ISC diary sends TTY logs of commands run by attackers or bots that successfully log into a sensor to the DShield SIEM every day.

According to the SANS ISC diary, published on 5 October 2026, the author wrote a script that parses and sends TTY logs collected from attacker or bot activity that runs several commands after successfully logging into a DShield sensor. The logs are sent at the end of each day to the DShield SIEM so they can be correlated with the rest of the data.

The text is an automatic translation of feed content and presents itself as a personal experiment. It does not describe results, metrics or conclusions beyond the sending flow, so this briefing is limited to what is stated.

The relevance lies in showing how honeypot telemetry can be centralized and correlated. Rota Nacional does not offer sensor log collection or SIEM correlation, and this briefing does not credit the platform with solving that engineering problem.

For readers who use AI to study this material: command logs can contain user names, addresses, host names or fragments with personal data. Before sending any excerpt to a model, remove or replace those values manually, because automatic detection covers CPF, CNPJ, e-mail, phone and person names, not necessarily network addresses or host names.

Consultation and verification: find the original diary in the SANS ISC feed by the date and title given, and confirm the script and references on the source page before any use.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free