logo

Non-interactive SSH attacks dominate after login

ID: 3544e5f0-1391-56f7-9a05-21af35ecbbdc

STIX ID: report--3544e5f0-1391-56f7-9a05-21af35ecbbdc

Feed Name: Help Net Security

Threat Score
15/100

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Sinisa Markovic

...
...

A study of eleven SSH honeypots (with corroboration from CZ.NIC data) found that 99%+ of authenticated sessions are non-interactive single-command probes—automated scanners confirming host characteristics—while interactive shells are rare. The most common commands gather basic system facts (uname, CPU count, uptime), and some scanners perform quick checks to detect honeypots or verify command execution; this trend has been dominant since ~2018 and affects how honeypot success should be measured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.