Skip to content
Discussion options

You must be logged in to vote

Zeek already logs ssh connections including the version and Hunt includes an SSH query for that:

Another option might be to write a Suricata rule:
https://suricata.readthedocs.io/en/suricata-6.0.0/rules/ssh-keywords.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants