Real-time alerts on SSH logins, and what do you do when one looks wrong?

A few non-technical people on our team upload files over SFTP with FileZilla, so password auth has to stay on for now. I know, keys only, FileZilla supports keys, a VPN would be better. It's on the list. fail2ban, strong passwords and a non-standard port are already there. What bugs me is detection. If one of those passwords leaks, I want to know the second someone logs in, not after files get messed with. What are you using for instant login alerts? A PAM script that hits a Telegram or Slack webhook, or something else? And if you catch a session you don't expect, what's your move? Just pkill -u and passwd -l , or do you have something smarter hooked into PAM?

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论