A SANS ISC researcher describes an experiment in which TTY logs are collected from activity on a DShield sensor. These logs record the commands that actors or bots execute after successfully logging in, offering a detailed view of post-compromise behavior.

The researcher created a script to parse these TTY logs and send them to the DShield SIEM. The transfer happens automatically at the end of each day, giving analysts a steady stream of attacker command data for review.

Because the source is a single diary entry, the article reflects one practitioner's approach rather than a broad industry consensus. Still, it highlights the value of TTY logging as a practical way to capture attacker actions that might otherwise go unnoticed.