CuraSec

Plan active

Automated SSH Attacks Achieve Persistence in ~22 Seconds

2026-08-06 13:03 UTC · SANS ISC · read the source ↗ #ssh#attack-automation#detection
  • Engineer — Learn: Research on automated SSH attack timelines underscores why key-only auth, login alerting, and session monitoring must be in place before an attacker lands — no specific patch needed, but validates hardening posture on any SSH-exposed host.
  • SOC/IR — Plan: The ~22-second login-to-persistence window is a concrete benchmark: review SSH authentication alert latency in your SIEM and ensure post-login activity (new cron jobs, authorized_keys writes, shell spawns) triggers faster than that window closes.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.