#!/usr/bin/env python3
import re
import sys
import argparse
def parse_logs(file_path):
unique_ips = set()
unique_users = set()
unique_passwords = set()
unique_commands = set()
unique_pubkeys = set()
# Regex patterns adjusted for your specific log format
# Extracts everything inside the first set of brackets after the timestamp
ip_bracket_pattern = re.compile(r'^\d{4}/\d{2}/\d{2} \d{2}:\d{2}:\d{2} \[([^\]]+)\]')
# Auth patterns
password_pattern = re.compile(r'authentication for user "([^"]+)" with password "([^"]*)"')
no_cred_pattern = re.compile(r'authentication for user "([^"]+)" without credentials')
pubkey_pattern = re.compile(r'authentication for user "([^"]+)" with (?:public )?key "([^"]+)"')
# Command pattern
command_pattern = re.compile(r'command "([^"]+)" requested')
try:
with open(file_path, 'r', encoding='utf-8', errors='ignore') as f:
for line in f:
line = line.strip()
# 1. Extract IP from the bracket header [IP:Port]
ip_match = ip_bracket_pattern.match(line)
if ip_match:
host_port = ip_match.group(1)
# Split from the rightmost colon to isolate the port
if ':' in host_port:
ip = host_port.rsplit(':', 1)[0].strip('[]')
unique_ips.add(ip)
# 2. Extract Username & Password
pwd_match = password_pattern.search(line)
if pwd_match:
unique_users.add(pwd_match.group(1))
unique_passwords.add(pwd_match.group(2))
continue
# 3. Extract Username from "without credentials" attempts
no_cred_match = no_cred_pattern.search(line)
if no_cred_match:
unique_users.add(no_cred_match.group(1))
continue
# 4. Extract Public Keys (if any exist in other parts of the log)
key_match = pubkey_pattern.search(line)
if key_match:
unique_users.add(key_match.group(1))
unique_pubkeys.add(key_match.group(2))
continue
# 5. Extract Commands
cmd_match = command_pattern.search(line)
if cmd_match:
unique_commands.add(cmd_match.group(1))
continue
except FileNotFoundError:
print(f"Error: The file '{file_path}' could not be found.", file=sys.stderr)
sys.exit(1)
except PermissionError:
print(f"Error: Missing permissions to read '{file_path}'.", file=sys.stderr)
sys.exit(1)
# Output Results
print_section("Unique Attacker IPs", unique_ips)
print_section("Targeted Usernames", unique_users)
print_section("Attempted Passwords", unique_passwords)
print_section("Public Keys Used", unique_pubkeys)
print_section("Attempted Commands / Payloads", unique_commands)
def print_section(title, data_set):
print(f"=== {title} ({len(data_set)}) ===")
if not data_set:
print(" (None found)")
else:
for item in sorted(data_set):
print(f" {item}")
print("\n")
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="Parse unique intelligence from your sshesame log format.")
parser.add_argument("logfile", help="Path to the sshesame text log file")
args = parser.parse_args()
parse_logs(args.logfile)