GithubHelp home page GithubHelp logo

zam89 / break-in-analyzer Goto Github PK

View Code? Open in Web Editor NEW
8.0 8.0 0.0 201 KB

Break-In Analyzer - A script that analyze auth.log, secure, utmp/wtmp for possible SSH break-in attempts

License: MIT License

Shell 100.00%
dfir digital-forensics forensics forensics-tools incident-response linux

break-in-analyzer's People

Contributors

zam89 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

break-in-analyzer's Issues

Cannot read Debian 11 auth log?

Nice job! Thanks for your code. One question, could it read debian 11 auth log? Right now it shows empty:

admin@ec2-184-169-203-102:~$ ./Break-In-Analyzer/break-in_analyzer.sh
_____________________________________
|				    |
|	Break-In Analyzer 1.2	    |
|___________________________________|

Please Select:
1) Analyze auth logs
2) Analyze secure logs
3) Analyze utmp/wtmp log
4) Exit script

* This script is checking for failed attempt on valid/existed account/username only!

Menu selection: 1
Input auth.log location..: /home/admin/var/log/auth.log

Possible Break-in Attempts - IP



Possible Break-in Attempts - Username



Successful Logins - IP



Successful Logins - Users


Done!

Here is the log:

$ more /home/admin/var/log/auth.log

Jan 28 00:00:11 web001 su: (to administrator) root on none
Jan 28 00:00:11 web001 su: pam_unix(su:session): session opened for user administrator by (uid=0)
Jan 28 00:00:11 web001 systemd: pam_unix(systemd-user:session): session opened for user administrator by (uid=0)
Jan 28 00:00:11 web001 su: pam_unix(su:session): session closed for user administrator
Jan 28 00:00:11 web001 su: (to administrator) root on none
Jan 28 00:00:11 web001 su: pam_unix(su:session): session opened for user administrator by (uid=0)
Jan 28 00:00:11 web001 su: pam_unix(su:session): session closed for user administrator
Jan 28 00:03:39 web001 sshd[28020]: Received disconnect from 92.118.39.84 port 56160:11: Bye Bye [preauth
]
Jan 28 00:03:39 web001 sshd[28020]: Disconnected from authenticating user root 92.118.39.84 port 56160 [p
reauth]
Jan 28 00:05:01 web001 CRON[28046]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 28 00:05:01 web001 CRON[28045]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 28 00:05:01 web001 CRON[28045]: pam_unix(cron:session): session closed for user root
Jan 28 00:05:02 web001 CRON[28046]: pam_unix(cron:session): session closed for user root
Jan 28 00:05:09 web001 su: (to administrator) root on none
Jan 28 00:05:09 web001 su: pam_unix(su:session): session opened for user administrator by (uid=0)
Jan 28 00:05:09 web001 systemd: pam_unix(systemd-user:session): session opened for user administrator by (uid=0)
Jan 28 00:05:09 web001 su: pam_unix(su:session): session closed for user administrator
Jan 28 00:05:09 web001 su: (to administrator) root on none
Jan 28 00:05:09 web001 su: pam_unix(su:session): session opened for user administrator by (uid=0)
Jan 28 00:05:09 web001 su: pam_unix(su:session): session closed for user administrator

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.