3 ms·
Incident response. When one of your admin accounts is compromised, you'd want to know what the attacker executed.
by _yy 11y ago
Incident response. When one of your admin accounts is compromised, you'd want to know what the attacker executed.
- ultramancool 11y agoYes you would - but why just SSH? Wouldn't auditd execve syscall logs sent to a logstash server be better? It'd handle compromises other than SSH too.
- _yy 11y agoYes - though there's more to a SSH session than executing commands (interacting with interactive editors, port forwarding, etc.)