One-click reference
journalctl --unit=sshd --since -24h --no-pager --output=short-precise
This action should be reviewed for the target environment before execution.
Forensics
Collect forensics-grade evidence from host and service telemetry before escalation.
All parsing is local. Build command snippets, copy them safely, and classify evidence severity in-browser.
Commands
journalctl --unit=sshd --since -24h --no-pager --output=short-precise
This action should be reviewed for the target environment before execution.
Severity map
Brute-force indicators, malware signatures, or unauthorized policy changes.
Credential anomalies, repeated auth failures, or suspicious command bursts.
Routine maintenance churn and known benign service rotation.
Analyzer
Total in this lab: 0
Related routes