Search and filter across all detection sources
13 rules
A Teleport Lock was created
A Teleport Role was modified or created
A long-lived cert was created
An unusually long-lived Teleport certificate was created
User Logged in wihout MFA
A local User logged in without MFA
A SAML Connector was created or modified
A SAML connector was created or modified
Teleport Scheduled Jobs
A user has manually edited the Linux crontab
Teleport Create User Accounts
A user has been manually created, modified, or deleted
User Logged in as root
A User logged in as root
Teleport SSH Auth Errors
A high volume of SSH errors could indicate a brute-force attack
A user authenticated with SAML, but from an unknown company domain
A User from the company domain(s) Logged in without SAML
Teleport Network Scan Initiated
A user has invoked a network scan that could potentially indicate enumeration of the network.
Teleport Suspicious Commands Executed
A user has invoked a suspicious command that could lead to a host compromise