logo

Covert Login Alerting

ID: f76fcc70-822e-574d-873b-f1d47af37172

STIX ID: report--f76fcc70-822e-574d-873b-f1d47af37172

Feed Name: SensePost Blog

Date Published: 2020-07-13

Date Updated: 2026-04-30

...
...

The post describes a defensive technique to detect use of compromised or canary credentials on Linux SSH by integrating a PAM hook (`pam_script`) that triggers a CanaryToken when specified credentials are attempted. It covers compiling and installing `pam_script`, adding `auth optional pam_script.so` to `/etc/pam.d/sshd`, and deploying a simple shell script that curls a token on authentication events to enable low-infrastructure alerting of suspicious login attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.