SSH watched country login notice from Zeek
Set up the zeek integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect the SSH watched country login notice.
Strategy
This rule monitors Zeek logs for the notice SSH::Watched_Country_Login
. The notice is generated if an SSH login is seen originating to or from a “watched” country based on the SSH::watched_countries
variable.
Triage and response
- Identify the owners of the host that has been accessed.
- Work with the team to understand if this authentication was expected/legitimate.
- If it is determined that the activity is malicious:
- Block the IP address, if it aligns with organization incident response processes.
- Begin your organization’s incident response process and investigate.