arXiv · 2204.04922
Active and Passive Collection of SSH key material for cyber threat intelligence
Abstract
This paper describes a system for storing historical forensic artefacts collected from SSH connections. This system exposes a REST API in a similar fashion as passive DNS databases, malware hash registries, and SSL notaries with the goal of supporting incident investigations and monitoring of infrastructure.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Alexandre Dulaunoy, Jean-Louis Huynen, Aurelien Thirion. 2022-04-11. Active and Passive Collection of SSH key material for cyber threat intelligence. https://doi.org/10.1145/3491262
Cite the original work for its findings. Save a collection to share your selection of sources.