Files
securityonion/salt/idh/Plays/IDH_SSH.yaml
T
2022-02-21 16:43:26 -05:00

18 lines
343 B
YAML

title: SO IDH - SSH Accessed
status: experimental
description: Detects when the SSH service on a SO IDH node has been probed.
author: Security Onion Solutions
logsource:
product: idh
detection:
selection:
event.code:
- 4000
- 4001
- 4002
condition: selection
falsepositives:
- None
fields:
- source.ip
level: critical