> For the complete documentation index, see [llms.txt](https://notes.cavementech.com/pentesting-quick-reference/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.cavementech.com/pentesting-quick-reference/brute-forcing-password-cracking/detecting-bruteforcing.md).

# Detecting Bruteforcing

## Linux

`/var/log/`, a Linux directory where all security events (logs) are stored. Indeed, every SOC analyst at TBFC will confirm that the best way to find evil bunnies is to check the logs. Log files are usually very big, and looking through them with cat is not ideal. Thus, let's use `grep`, a command to look for a specific text inside a file.

* Navigate to the logs directory with `cd /var/log` and explore its content with `ls`.
* Run `grep "Failed password" auth.log` to look for the failed logins inside the `auth.log`.

<figure><img src="/files/GXRVzjWZg4pagXKZ1ci3" alt=""><figcaption></figcaption></figure>
