


Perceptive Security
SOC/SIEM Consultancy

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
Published:
6 August 2026 at 02:15:40
Alert date:
6 August 2026 at 03:01:36
Source:
isc.sans.edu
Network Infrastructure, Identity & Access, Operating Systems
This guest diary by Daryl Jiminez, an ISC intern in the SANS.edu BACS program, investigates the speed at which automated SSH threat actors can move from initial login to establishing persistence on a compromised system. The article highlights that the entire compromise chain can occur in as little as 22 seconds, before most defenders can even react. The research underscores the danger of automated attack tooling targeting SSH services exposed to the internet. It emphasizes how quickly attackers leverage valid or brute-forced credentials to deploy backdoors, create user accounts, or install malware. The findings stress the critical need for proactive SSH hardening, monitoring, and rapid automated response capabilities to counter such fast-moving threats.
Technical details
Mitigation steps:
Affected products:
SSH
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
