I came across that Detection Rule but it seems unusual to me that i cannot specify the "Forbidden Times" somehow. My guess is that auditd has that event that can be triggered but the thing is that somehow you can control that and set your "forbidden hours".
The query is: event.module:auditd and event.action:"attempted-log-in-during-unusual-hour-to"
Also i couldn't find any documentation about that event from auditd.
Hi again, @panagiss, for this rule, auditbeat is checking details available in a Linux Pluggable Authentication Module, also known as PAM, on the system on which it is running.
Specifically, there is a pam_time module that detects logins during unusual times. I am not familiar with this module, but it seems that there are time settings available.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.