Splunk lab detecting SSH brute-force attacks using failed login events, alerts, and dashboards.
-
Updated
Jan 5, 2026
Splunk lab detecting SSH brute-force attacks using failed login events, alerts, and dashboards.
tool to retrieve and analyze server or domain controller login logs — audit user IP associations, authentication trails, logon sessions, and security event logs for forensic investigation and Active Directory monitoring.
Investigated Ubuntu authentication logs for failed logins, SSH activity, unknown users, and suspicious sudo commands.
Blue Team lab for detecting and analyzing repeated failed SSH login attempts through Linux authentication logs in an isolated environment.
This project demonstrates detection of SSH brute-force attempts on a Linux system using Splunk Enterprise. It simulates SOC analyst workflows: detection, alerting, investigation, and documentation. (In Phases)
Python tool for analyzing authentication logs, identifying suspicious login activity, and generating SOC-style findings.
A Python defensive-security tool that detects brute-force attempts, targeted accounts and suspicious authentication activity.
🔍 Detect SSH brute-force attacks with ease using Splunk, leveraging real-time alerts and visual dashboards from simulated Linux authentication logs.
Add a description, image, and links to the authentication-logs topic page so that developers can more easily learn about it.
To associate your repository with the authentication-logs topic, visit your repo's landing page and select "manage topics."