Syslog

Syslog is the standard protocol for shipping log events from systems and devices to a central collector or SIEM, classically over UDP 514 with no authentication and no integrity protection (TCP and TLS variants exist but are far less common). The entire monitoring and detection pipeline downstream trusts those records, and that trust is the attack surface. An attacker on the network spoofs the source address of records to attribute forged logs to other hosts, injects crafted and newline-split entries to forge events and poison the parsers and correlation rules the SIEM depends on, and floods the collector to drown real signal or disrupt the pipeline. The goal is usually to mislead operators, hide activity, or exploit a downstream log-processing sink.

bash
# send an arbitrary syslog record (UDP 514)
logger -n <collector> -P 514 -d "test from attacker"
echo '<34>1 2025-01-01T00:00:00Z host app - - - forged event' | nc -u -w1 <collector> 514

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more