SSH Brute Force: High-Frequency Auth Failures and Rapid Connection Attempts
This rule detects potential SSH brute force attacks by identifying high-frequency authentication failures from sshd logs (more than 10 failures in 5 minutes) and rapid, potentially automated connection attempts on port 22 (more than 20 connections in 1 minute) originating from the same source IP on Linux systems.
SentinelOne

