Regional Telecom
A telecom operator caught a live SSH breach across 400 sites
The problem
A regional telecom operator ran infrastructure across hundreds of remote sites in several countries — exactly the kind of distributed fleet where centralized monitoring has blind spots. Auth logs lived on the hosts; nobody was reading them in real time.
The detection
Within the first week of deployment, an AutoOps agent flagged a success-after- failure pattern on a site gateway — repeated failed SSH logins from a single source, followed by a success. The centralized SIEM hadn't surfaced it; the signal never made it off the host in a form anyone was watching.
AutoOps caught it on the host, in real time, with the evidence attached: source IP, failed attempt count, usernames tried.
The response
The recommendation — the exact block command for that host — went to the operator's NOC. A human confirmed and ran it. The compromised access was cut within minutes, not discovered days later in a log review.
The results
- 400+ remote sites brought under continuous, on-host watch
- A live breach caught in week one that centralized tooling had missed
- Detection that works where the fleet actually is — not just where the SIEM can reach
Why on-host mattered
For a geographically distributed fleet, the lesson was blunt: the detection has to live where the evidence lives. An agent on the host saw what remote polling structurally couldn't.