home

parse auth.log / secure · SSH brute force · sudo · privilege escalation

Drop auth.log or /var/log/secure
Linux: /var/log/auth.log · /var/log/secure · journalctl -u sshd
drop /var/log/auth.log · /var/log/secure · or Windows Security EVTX CSV
ready