Man or Machine?
Lets run the pcap through the ssh protocols
Looking for interesting metrics in the log output. ssh.log doesn't show much. However in the conn.log we find the following line.
We find this entry had substantially more orig_ip_bytes
The solution
Last updated
Was this helpful?