New SSH Username Report, (Sun, Apr 6th)
ID: bf6df273-3366-5b9a-8f0a-766b1681fb9c
STIX ID: report--bf6df273-3366-5b9a-8f0a-766b1681fb9c
Feed Name: SANS ISC Diary
Honeypot telemetry from Cowrie highlights newly observed SSH/Telnet brute-force usernames over the past 30 days, including typos, first-initial/last-name patterns, admin-themed accounts (e.g., dbmasteruser), and mistakes like supplying a wordlist file path as a username—underscoring that attackers err and no username is inherently safe; a JSON feed of recent usernames is available for further analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
