SSH Shell Attacks
An analysis of attacker behaviour in 230,000 honeypot-captured Unix shell attacks.
The problem
Large collections of shell commands reveal attacker behaviour, but their volume makes manual analysis impractical.
Contribution
I analysed 230,000 Unix shell attacks captured by a honeypot using machine-learning and NLP techniques. The work classifies attacker intent and relates recurring behaviour to MITRE ATT&CK tactics.
Why it matters
The project shows how raw operational telemetry can become structured evidence for threat detection and intelligence work.
