Yeah, but then you would have ssh traffic without a matching login.
Wonder if any anomaly detection would work on that
Wonder if any anomaly detection would work on that
I’m not aware of any services that a) work like this, or b) would be able to detect this class of attack earlier than last week. If someone does though, please share.
This kind of anomaly detection is possible. Not sure how common it is. I doubt it is common.
An EDR tool would be much better to look for an attacker’s next steps. But if you’re trying to catch a nation state they probably already have a plan for hiding their tracks.