← All projects
Security & networking · Python
LS

logsentinel

SSH brute-force detector — paste auth.log lines and watch sliding-window rules fire, entirely in your browser.

1 Authentication log

Classic syslog timestamps (Sep 17 03:00:00) or RFC 3339. Year defaults to 2026 to match the sample.

Loaded with samples/auth.log — synthetic, documentation IP ranges only.

2 Detection settings

Parsed lines
0
Failed logins
0
Invalid users
0
Successful
0
Alerts
0

3 Findings

4 Timeline

Events and alerts in chronological order. Red = failure, green = success, amber ring = alert raised.

5 Threat timeline visualization

Failures bucketed over the log window — bar height = failure count, color = highest severity of alerts in that bucket.

critical high medium hover a bar for details

6 MITRE ATT&CK technique mapping

Alerts mapped to Enterprise ATT&CK techniques. Counts update with each Detect run.

7 Source IP classification

RFC-aware classification only — private, loopback, link-local, documentation (TEST-NET), multicast/reserved, or public. Well-known Tor exit nodes are checked against a small embedded list; no fake geolocation.

8 Severity scoring breakdown

Each alert gets a 0–100 score from weighted factors: rule base severity, failure volume, distinct users, success-after-failures, and source classification.

score = base + volume + spray + critical-boost + source-adjustment

9 Live attack simulation

Generates synthetic auth.log lines (brute force / spray / success-after-failures) and feeds them to the real detector in real time. Watch alerts appear as the stream runs.

stopped
Simulation idle — press Start.

10 Export findings

Download current alerts as JSON (SAROM-like schema) or copy to clipboard for pasting into a ticket / SIEM.

Run Detect, then export.

Detection rules

RuleFires whenSeverity
brute_forceone IP has ≥ threshold failures in the windowhigh
password_sprayone IP tries ≥ spray distinct usernamesmedium
success_after_failureslogin succeeds after ≥ half-threshold recent failurescritical

The window slides per IP. Lower the threshold or raise the window to catch slower attacks.

What the sample contains

  • 198.51.100.23 — 40 failures on root in ~4 minutes → brute force
  • 203.0.113.77 — 8 distinct usernames → password spray
  • 2001:db8::42 — 7 failures on alice, then success → critical
  • 192.0.2.55 — 2 failures then success (under threshold, no alert)

Invalid-user lines are deduplicated within 5 seconds so sshd's double-logging counts once.

20 tests · Python 3.10+ · standard library only · Built by Umer Hashmi