SSH Brute Force via High-Volume SSH Handshake Packets
Detects high-volume SSH authentication attempts originating from a single source IP targeting a server on port 22, indicating a potential brute force attack.
Suricata

Detects high-volume SSH authentication attempts originating from a single source IP targeting a server on port 22, indicating a potential brute force attack.

Already have an account?