7.1 KiB
+++ title = "Logging & Syslog" chapter = false weight = 50 pre = "6. " +++
📊 Logging & Syslog
Cazalla includes a complete logging system that records all Mythic events and sends them to a central syslog server for analysis and auditing.
🎯 Description
Cazalla's logging system:
- ✅ Logs ALL events from Mythic automatically
- ✅ Does not modify the agent (avoids detections)
- ✅ Runs on the server, not on the target
- ✅ Sends logs to syslog central for analysis
- ✅ Saves local logs as backup
- ✅ Structured JSON format for easy parsing
📋 Logged Events
The logger automatically captures all these events:
| Event | Description |
|---|---|
| CALLBACK | When an agent connects or checks in |
| TASK | When a task is created or updated (commands executed) |
| RESPONSE | Agent responses (command output) |
| CREDENTIAL | Captured credentials |
| KEYLOG | Keystrokes captured by the keylogger |
| FILE | Files uploaded or downloaded |
| ARTIFACT | Generated artifacts (IOCs, processes created, etc.) |
| PAYLOAD | Created payloads |
⚙️ Configuration
Step 1: Configure the Logger
The logger is configured via a configuration file. You don't need to modify docker-compose.yml.
-
Edit the configuration file:
nano Payload_Type/cazalla/logger/syslog.conf -
Configure the syslog server IP:
# If rsyslog is on the same host as Mythic, use the host IP SYSLOG_SERVER=10.8.20.50 # Or if using Docker bridge SYSLOG_SERVER=172.17.0.1 # Port (default 514) SYSLOG_PORT=514 # Syslog facility (16 = LOCAL0, recommended) SYSLOG_FACILITY=16 -
Rebuild and restart the container:
cd /opt/mythic sudo ./mythic-cli build cazalla sudo ./mythic-cli restart cazalla
Step 2: Configure rsyslog on the Host (Optional)
If you want to receive logs on the same server where Mythic runs:
-
Install rsyslog (if not installed):
sudo apt-get update && sudo apt-get install -y rsyslog -
Enable UDP reception in
/etc/rsyslog.conf:sudo sed -i 's/#module(load="imudp")/module(load="imudp")/' /etc/rsyslog.conf sudo sed -i 's/#input(type="imudp" port="514")/input(type="imudp" port="514")/' /etc/rsyslog.conf -
Create rule for Cazalla in
/etc/rsyslog.d/50-cazalla.conf:sudo bash -c 'cat > /etc/rsyslog.d/50-cazalla.conf << EOF # Logs from Cazalla Mythic agent # Filter by facility LOCAL0 (16) if \$syslogfacility-text == "local0" then /var/log/cazalla.log & stop EOF ' -
Restart rsyslog:
sudo systemctl restart rsyslog sudo systemctl enable rsyslog -
Verify it's listening:
sudo netstat -ulnp | grep 514 # You should see: UNCONN ... 0.0.0.0:514 ... rsyslogd
📊 Verification
Verify Logger is Active
# View container logs
sudo docker logs cazalla | grep -i "syslog\|Logger initialized"
# You should see:
# INFO:cazalla_logger:Syslog client initialized: 10.8.20.50:514 (facility=16)
# INFO:cazalla_logger:Logger initialized: cazalla_logger
View Logs in Real-Time
# View logs in syslog (host)
sudo tail -f /var/log/cazalla.log
# View local logs (inside container)
sudo docker exec cazalla tail -f /tmp/cazalla_mythic_$(date +%Y-%m-%d).log
View Specific Events
# View only tasks
sudo tail -100 /var/log/cazalla.log | grep '"event_type": "TASK"'
# View only responses
sudo tail -100 /var/log/cazalla.log | grep '"event_type": "RESPONSE"'
# Count events by type
sudo tail -1000 /var/log/cazalla.log | grep -o '"event_type": "[^"]*"' | sort | uniq -c
📝 Log Format
Logs are saved in structured JSON format for easy parsing:
{
"event_type": "TASK",
"timestamp": "2025-11-17T15:18:23.117715674Z",
"operation_id": 1,
"operation_name": "Operation Chimera",
"username": "mythic_admin",
"action": "new_task",
"server_name": "mythic",
"data": {
"id": 18,
"command_name": "shell",
"params": "{\"command\":\"whoami\"}",
"status": "success",
"callback_id": 2,
"operator_username": "mythic_admin",
...
}
}
Log Locations
- Syslog (host):
/var/log/cazalla.log - Local logs (container):
/tmp/cazalla_mythic_YYYY-MM-DD.log- One file per day
- No rotation (all files are kept)
- Format:
cazalla_mythic_2025-11-17.log
🔍 Usage Examples
Search for a Specific Command
# Search for all 'whoami' executions
sudo grep -i "whoami" /var/log/cazalla.log | grep '"event_type": "TASK"'
View Operator Activity
# View all events from a user
sudo grep '"username": "mythic_admin"' /var/log/cazalla.log
View Captured Credentials
# View credential events
sudo grep '"event_type": "CREDENTIAL"' /var/log/cazalla.log
Analyze Generated Artifacts
# View all artifacts (detected IOCs)
sudo grep '"event_type": "ARTIFACT"' /var/log/cazalla.log
🛠️ Troubleshooting
Logger Doesn't Appear in Mythic GUI
Solution:
- Verify the logger is imported in
main.py - Rebuild the container:
sudo ./mythic-cli build cazalla - Restart:
sudo ./mythic-cli restart cazalla
Don't See "Syslog client initialized"
Solution:
- Verify
SYSLOG_SERVERhas a value insyslog.conf:sudo docker exec cazalla cat /Mythic/logger/syslog.conf | grep SYSLOG_SERVER - Rebuild the container if you just edited the file
Messages Not Reaching Syslog
Solution:
- Verify rsyslog is listening:
sudo netstat -ulnp | grep 514 - Verify connectivity from container to host
- Verify rsyslog configuration:
sudo cat /etc/rsyslog.d/50-cazalla.conf - Verify firewall:
sudo iptables -L -n | grep 514
Logs Are Empty
Solution:
- Logs only appear when there's activity in Mythic
- Execute a command on an agent to generate events
- Verify the agent is connected and active
📚 Advanced Configuration
Change Syslog Facility
The syslog facility determines how messages are categorized. By default, 16 (LOCAL0) is used.
To change the facility, edit syslog.conf:
# Use AUTH (4) for security logs
SYSLOG_FACILITY=4
# Or use LOCAL1 (17)
SYSLOG_FACILITY=17
Then update the rsyslog rule to filter by the new facility.
Send to Multiple Syslog Servers
To send to multiple servers, you would need to modify the logger code or use an intermediate syslog server that forwards messages.
SIEM Integration
The JSON formatted logs can be easily integrated with SIEMs such as:
- Splunk
- ELK Stack (Elasticsearch, Logstash, Kibana)
- Graylog
- QRadar
Simply configure the SIEM to read from /var/log/cazalla.log or from the central syslog server.
🔗 References
Note: The logging system is active by default. You only need to configure the syslog server if you want to centralize logs.