SSH password guessing notice from Zeek
Set up the zeek integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect the SSH password guesser notice.
Strategy
This rule monitors Zeek logs for the notice SSH::Password_Guessing
. The notice is generated when a host exceeds the failed logins SSH::password_guesses_limit
threshold.
Triage and response
- Identify the owners of the host that has been accessed.
- Work with the team to understand if this authentication was expected/legitimate.
- If it is determined that the activity is malicious:
- Block the IP address, if it aligns with organization incident response processes.
- Begin your organization’s incident response process and investigate.