Skip to content

Conversation

@Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Feb 21, 2025

Summary

This rule monitors the authentication logs for messages related to instances of a first-time public key authentication. Public key authentication is a secure method for authenticating users to a server. Monitoring first-time public key authentication events can help detect unauthorized access attempts or suspicious activity on the system.

Telemetry

{270CC691-E446-40BC-AC43-BD2BBA22136B}
@tradebot-elastic
Copy link

tradebot-elastic commented Feb 21, 2025

⛔️ Tests failed:

@tradebot-elastic
Copy link

tradebot-elastic commented Feb 27, 2025

⛔️ Tests failed:

@Aegrah Aegrah changed the title [New Rule] First Time Public Key Authentication [New Rule] Successful SSH Authentication from Unusual SSH Public Key Feb 27, 2025
@tradebot-elastic
Copy link

tradebot-elastic commented Feb 27, 2025

⛔️ Tests failed:

Copy link
Contributor

@DefSecSentinel DefSecSentinel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tradebot-elastic
Copy link

tradebot-elastic commented Feb 27, 2025

⛔️ Tests failed:

@Aegrah Aegrah merged commit 89f79c6 into main Feb 28, 2025
10 checks passed
@Aegrah Aegrah deleted the new-public-key-authentication branch February 28, 2025 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment