To analyze Linux authentication logs and identify malicious login attempts and privilege escalation activity.
- Linux (Ubuntu)
- grep, awk, tail
- journalctl
- Detected multiple failed SSH login attempts
- Identified attacker IP addresses
- Analyzed targeted usernames
- Observed failed privilege escalation attempts
- Linux log analysis
- Security investigation
- Incident detection
- SOC analyst fundamentals