A low/zero interaction ssh authentication logging honeypot. Structured logging ssh-auth-logger logs all authentication attempts as json making it easy to consume in other tools. No more ugly openssh log parsing vulnerabilities. This is normally logged on one line { "client_version": "SSH-2.0-libssh2_1.4.3", "destinationServicename": "sshd", "dpt": "22", "dst": "192.168.1.2", "duser": "root", "level": "info", "msg": "Request with password", "password": "P@ssword1", "product": "ssh-auth-logger", "server_version": "SSH-2.0-OpenSSH_5.3", "spt": "38624", "src": "192.168.1.4", "time": "2017-11-17T19:16:37-05:00" }
Common questions about ssh-auth-logger including features, pricing, alternatives, and user reviews.
ssh-auth-logger is A low-interaction SSH authentication logging honeypot that logs all authentication attempts in JSON format. It is a Security Operations solution designed to help security teams with SSH.
ssh-auth-logger is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/JustinAzoff/ssh-auth-logger/ for download and installation instructions.
Popular alternatives to ssh-auth-logger include:
Compare these tools and more at https://cybersectools.com/categories/security-operations
ssh-auth-logger is for security teams and organizations that need SSH. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
A modified version of OpenSSH deamon forwarding commands to Cowrie for logging brute force attacks and shell interactions.