AutoOps AI
All case studies

Regional Telecom

A telecom operator caught a live SSH breach across 400 sites

400+remote sites under watch

The problem

A regional telecom operator ran infrastructure across hundreds of remote sites in several countries — exactly the kind of distributed fleet where centralized monitoring has blind spots. Auth logs lived on the hosts; nobody was reading them in real time.

The detection

Within the first week of deployment, an AutoOps agent flagged a success-after- failure pattern on a site gateway — repeated failed SSH logins from a single source, followed by a success. The centralized SIEM hadn't surfaced it; the signal never made it off the host in a form anyone was watching.

AutoOps caught it on the host, in real time, with the evidence attached: source IP, failed attempt count, usernames tried.

The response

The recommendation — the exact block command for that host — went to the operator's NOC. A human confirmed and ran it. The compromised access was cut within minutes, not discovered days later in a log review.

The results

  • 400+ remote sites brought under continuous, on-host watch
  • A live breach caught in week one that centralized tooling had missed
  • Detection that works where the fleet actually is — not just where the SIEM can reach

Why on-host mattered

For a geographically distributed fleet, the lesson was blunt: the detection has to live where the evidence lives. An agent on the host saw what remote polling structurally couldn't.