Elia Innocenti
← Projects

SSH Shell Attacks

An analysis of attacker behaviour in 230,000 honeypot-captured Unix shell attacks.

Role
Machine-learning and threat-analysis project
Focus
Threat intelligence · Honeypot telemetry · MITRE ATT&CK

The problem

Large collections of shell commands reveal attacker behaviour, but their volume makes manual analysis impractical.

Contribution

I analysed 230,000 Unix shell attacks captured by a honeypot using machine-learning and NLP techniques. The work classifies attacker intent and relates recurring behaviour to MITRE ATT&CK tactics.

Why it matters

The project shows how raw operational telemetry can become structured evidence for threat detection and intelligence work.