Kamalpreet Singh AI-Powered Cybersecurity Mastery — IIT Madras GitHub
This project investigates and mitigates brute force attack patterns across system and network layers using Kali Linux.
Completed as part of IIT Madras AI-Powered Cybersecurity Mastery Program Course 2 — Designing Secure Systems Networks and Devices.
Company: SecureCore Technologies
A mid-sized enterprise detected surge in failed login attempts on critical servers. Despite active security systems deeper log analysis revealed ongoing brute force attacks targeting weak credentials and misconfigured policies.
Investigate and mitigate brute force attack patterns by:
- Analyzing system logs
- Auditing user accounts
- Reviewing firewall rules
- Analyzing encrypted files
- Identifying unauthorized access
| Tool | Purpose |
|---|---|
| Kali Linux | Investigation platform |
| Hydra | Brute force simulation |
| Wireshark | Packet analysis |
| iptables | Firewall inspection |
| rsyslog | Log capture |
| GPG | Encryption analysis |
| ent | Entropy analysis |
Established system baseline including OS version kernel network configuration running services and disk usage.
Commands:
sudo apt update && sudo apt upgrade -y
uname -a
ip addr
ss -tulpn
df -h
free -hInvestigated accounts and permissions to identify weak credentials and unauthorized access points.
Key Findings:
- postgres had interactive bash shell
- kali-trusted had NOPASSWD sudo access
- No unauthorized UID 0 accounts
- No passwordless accounts detected
Examined firewall configuration open ports and active network connections.
Critical Finding: All iptables chains set to ACCEPT with zero filtering rules active. Completely open firewall detected.
This task demonstrates a full before-and-after analysis of an SSH brute force attack, showing the system's vulnerability without protection and the effectiveness of Fail2Ban as a mitigation control.
The SSH service was started with no brute-force protection in place. Hydra was used to launch a dictionary attack using the rockyou.txt wordlist. With nothing blocking repeated attempts, thousands of password tries were sent continuously to the SSH service.
Step 1 — Start SSH Service
sudo service ssh start
sudo service ssh statusSSH service started successfully and is confirmed active on port 22.
Figure 1: SSH service started and confirmed active on port 22
Step 2 — Launch Hydra Brute-Force Attack (No Protection)
hydra -l red -P /usr/share/wordlists/rockyou.txt ssh://127.0.0.1 -t 4 -VHydra launched 14,344,399 login attempts using 4 parallel threads. With no Fail2Ban active, every attempt reached the SSH service without being blocked or throttled.
Figure 2: Hydra sending unrestricted brute-force attempts — no protection active
Step 3 — Failed Attempts Logged in auth.log
grep "Failed password" /var/log/auth.log | tail -20The auth.log file recorded a continuous stream of failed password attempts from 127.0.0.1 every 1–3 seconds, confirming the attack was reaching the SSH service with no intervention.
Figure 3: auth.log showing rapid failed SSH login attempts with no banning
Step 4 — Install Fail2Ban
sudo apt install fail2ban -yFail2Ban installed successfully along with its dependency python3-systemd.
Figure 4: Fail2Ban installed via apt package manager

Step 5 — Configure the SSH Jail
The Fail2Ban SSH jail was configured with the following settings:
[sshd]
enabled = true
port = 22
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 600
findtime = 600
backend = auto
ignoreself = false
Setting ignoreself = false ensures the loopback address (127.0.0.1) is not exempt from banning, which is critical for this local simulation.
Figure 5: Fail2Ban SSH jail configuration in nano
Step 6 — Start Fail2Ban and Verify Baseline Status
sudo service fail2ban start
sudo service fail2ban status
sudo fail2ban-client status sshdFail2Ban started successfully and confirmed active. The initial jail status showed zero failed attempts and no banned IPs, confirming a clean baseline before re-running the attack.
Figure 6: Fail2Ban service active and running
Figure 7: Fail2Ban sshd jail showing 0 failed attempts and empty banned IP list
Step 7 — Re-run Hydra Attack — Blocked and IP Banned
hydra -l red -P /usr/share/wordlists/rockyou.txt ssh://127.0.0.1 -t 4 -V
sudo fail2ban-client status sshdWhen Hydra was launched again, it immediately received a Connection refused error instead of attempting passwords. The Fail2Ban jail status confirmed 13 total failed attempts, 1 currently banned IP, and 127.0.0.1 in the banned IP list. The mitigation was fully effective.
Figure 8: Hydra blocked with Connection refused; Fail2Ban showing 127.0.0.1 banned after 13 failed attempts
Simulation Summary:
| Before Fail2Ban | After Fail2Ban | |
|---|---|---|
| Hydra result | Unlimited attempts | Connection refused |
| auth.log | Flooded with failures | Attack stopped |
| Banned IPs | None | 127.0.0.1 |
| Total failed attempts | Thousands | 13 (then blocked) |
| Protection | ❌ None | ✅ Active |
Scanned for encrypted files using entropy analysis to detect hidden data.
Results:
| File | Entropy | Conclusion |
|---|---|---|
| normal.txt | 3.6 bits/byte | Plain text |
| secret.txt.gpg | 6.24 bits/byte | Encrypted |
Deep analysis of authentication logs to uncover complete attack picture.
Findings:
- 20 failed attempts recorded
- Attack every 1-3 seconds
- Confirms automated tool
- No successful login
- Started 14/05/2026 at 20:30
Analyzed two packet capture files to detect network intrusion attempts.
File 1 — NmapScanANDDoS.pcapng:
- Nmap SYN stealth scan detected
- Fingerprint Win=1024 MSS=1460
- SYN flood DoS identified
- Attacker: 192.168.12.131
File 2 — MITM.pcapng:
- ARP cache poisoning detected
- Man in middle attack confirmed
- ICMP redirects identified
| Finding | Risk | Mitigated |
|---|---|---|
| Open firewall | Critical | ✅ Yes |
| postgres bash shell | High | ✅ Yes |
| kali-trusted NOPASSWD | High | ✅ Yes |
| SSH brute force | High | ✅ Yes |
| ARP poisoning | Critical | ✅ Detected |
| Nmap SYN scan | Medium | ✅ Detected |
sudo iptables -A INPUT -m state \
--state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A INPUT -p tcp \
--dport 22 -s 192.168.64.0/24 -j ACCEPT
sudo iptables -P INPUT DROP
sudo iptables-save > \
/etc/iptables/rules.v4sudo apt install fail2ban -y
sudo service fail2ban start
# Set MaxAuthTries 3
# Set PermitRootLogin no
# Set PasswordAuthentication no
sudo service ssh restartchmod 700 /home/red/.ssh
chmod 700 /home/red/.gnupg
md5sum /home/red/* > baseline.txt| Component | Detail |
|---|---|
| Platform | VMware Workstation Pro |
| OS | Kali Linux |
| RAM | 8GB |
| CPU | 2 Cores |
| Network | NAT Mode |
Figure 1: SSH service started and confirmed active on port 22
Figure 2: Hydra sending unrestricted brute-force attempts — no protection active
Figure 3: auth.log showing rapid failed SSH login attempts with no banning
Figure 4: Fail2Ban installed via apt package manager
Figure 5: Fail2Ban service active and running
Figure 6: Fail2Ban sshd jail showing 0 failed attempts and empty banned IP list
Figure 7: Fail2Ban SSH jail configuration in nano
Figure 8: Hydra blocked with Connection refused; Fail2Ban showing 127.0.0.1 banned after 13 failed attempts
Original Task 4 Screenshots:
- How brute force attacks work in real time
- Detecting attacks through log analysis
- Hardening SSH and firewall configurations
- Using entropy to identify encrypted data
- How ARP poisoning enables MITM attacks
- How Nmap SYN scans fingerprint targets
- Applying practical mitigation techniques
Program: AI-Powered Cybersecurity Mastery Institute: IIT Madras Course: Designing Secure Systems Networks and Devices Status: Completed ✅
GitHub: kamal301096
Completed in isolated lab environment for educational purposes only