SSH brute-force detection and attack timeline reconstruction using Linux auth.log and wtmp — no SIEM, just grep, cut, sort, and uniq.
-
Updated
Aug 4, 2026
SSH brute-force detection and attack timeline reconstruction using Linux auth.log and wtmp — no SIEM, just grep, cut, sort, and uniq.
Developed a log analysis system to detect security incidents, reconstruct attack timelines, and identify malicious activity using Linux and Windows logs, demonstrating blue-team threat detection and incident response skills.
Real-time SSH brute-force and password spraying detection engine written in Go.
Custom SOC pipeline with ELK stack, Logstash, Sigma rules, and Kibana dashboards for threat detection.
Interactive Splunk dashboard for SSH brute-force detection with SPL-based failed login analysis and geo-visualization of attack origins.
To associate your repository with the bruteforcedetection topic, visit your repo's landing page and select "manage topics."