This article describes a system for storing historical forensic artifacts collected from SSH connections. This system exposes a REST API in a similar fashion as passive DNS databases, malware hash registries, and SSL notaries with the goal of supporting incident investigations and monitoring of infrastructure.
No takes yet. Share an insight, caveat, or question.
Dulaunoy et al. (2021) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: