logsentinel
SSH brute-force detector — paste auth.log lines and watch sliding-window rules fire, entirely in your browser.
1 Authentication log
Classic syslog timestamps (Sep 17 03:00:00) or RFC 3339. Year defaults to 2026 to match the sample.
Loaded with samples/auth.log — synthetic, documentation IP ranges only.
2 Detection settings
3 Findings
4 Timeline
Events and alerts in chronological order. Red = failure, green = success, amber ring = alert raised.
5 Threat timeline visualization
Failures bucketed over the log window — bar height = failure count, color = highest severity of alerts in that bucket.
6 MITRE ATT&CK technique mapping
Alerts mapped to Enterprise ATT&CK techniques. Counts update with each Detect run.
7 Source IP classification
RFC-aware classification only — private, loopback, link-local, documentation (TEST-NET), multicast/reserved, or public. Well-known Tor exit nodes are checked against a small embedded list; no fake geolocation.
8 Severity scoring breakdown
Each alert gets a 0–100 score from weighted factors: rule base severity, failure volume, distinct users, success-after-failures, and source classification.
9 Live attack simulation
Generates synthetic auth.log lines (brute force / spray / success-after-failures) and feeds them to the real detector in real time. Watch alerts appear as the stream runs.
10 Export findings
Download current alerts as JSON (SAROM-like schema) or copy to clipboard for pasting into a ticket / SIEM.
Detection rules
| Rule | Fires when | Severity |
|---|---|---|
| brute_force | one IP has ≥ threshold failures in the window | high |
| password_spray | one IP tries ≥ spray distinct usernames | medium |
| success_after_failures | login succeeds after ≥ half-threshold recent failures | critical |
The window slides per IP. Lower the threshold or raise the window to catch slower attacks.
What the sample contains
- 198.51.100.23 — 40 failures on
rootin ~4 minutes → brute force - 203.0.113.77 — 8 distinct usernames → password spray
- 2001:db8::42 — 7 failures on
alice, then success → critical - 192.0.2.55 — 2 failures then success (under threshold, no alert)
Invalid-user lines are deduplicated within 5 seconds so sshd's double-logging counts once.