# How do you specify the "forbidden hours" in the Detection Rule "Auditd Login Attempt at Forbidden Time"

**URL:** <https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [July 27, 2021, 9:57am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713 "2021-07-27T09:57:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [July 27, 2021, 9:57am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713/1 "2021-07-27T09:57:11Z")

</div>

I came across that Detection Rule but it seems unusual to me that i cannot specify the "Forbidden Times" somehow. My guess is that auditd has that event that can be triggered but the thing is that somehow you can control that and set your "forbidden hours".

The query is: `event.module:auditd and event.action:"attempted-log-in-during-unusual-hour-to"`  
Also i couldn't find any documentation about that event from auditd.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [July 28, 2021, 11:21am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713/2 "2021-07-28T11:21:29Z")

</div>

Hi again, @panagiss, for this rule, auditbeat is checking details available in a Linux Pluggable Authentication Module, also known as PAM, on the system on which it is running.

Specifically, there is a `pam_time` module that detects logins during unusual times. I am not familiar with this module, but it seems that there are time settings available.

I found this Red Hat documentation on [Time-based restriction of Access](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/chap-security_guide-securing_your_network#sect-Security_Guide-Workstation_Security-Time-based_Restriction_of_Access)

So your linux system would need to have `pam_time` installed and running in order for this rule to trigger.

The [Elastic documentation for this rule](https://www.elastic.co/guide/en/security/current/auditd-login-attempt-at-forbidden-time.html#auditd-login-attempt-at-forbidden-time) contains a link to the [line in the pam\_time code](https://github.com/linux-pam/linux-pam/blob/aac5a8fdc4aa3f7e56335a6343774cc1b63b408d/modules/pam_time/pam_time.c#L666) that checks for this behavior.

Hope this helps!

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [July 28, 2021, 11:29am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713/3 "2021-07-28T11:29:30Z")

</div>

Yeah thanks, i didn't see the link at first, even thought your info here was more valuable for me in order to dig it up later.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2021, 11:30am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713/4 "2021-08-25T11:30:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
