SSH Brute-Force - 10+ Failed Auth Attempts in 60s from Single Source
Detects multiple failed SSH authentication attempts originating from a single source IP within a short timeframe, which is indicative of a brute-force or credential-stuffing attack against SSH services.
Suricata

