Where a Linux logon session's host places it relative to your networks, classified from the session's recorded host. A remote root logon from a public address or a hostname is a strong sign of an exposed service or stolen credentials.
Values
| Enum Value | Description |
|---|---|
|
|
No remote host, a local X display, or a loopback address. |
|
|
A private (RFC 1918 or IPv6 unique local) or link-local address. |
|
|
Any other IP address, including carrier-grade NAT (100.64.0.0/10) and IPv4-mapped public addresses. |
|
|
A hostname rather than an address, including a bare "localhost". It's never trusted as the address it may resolve to, since reverse DNS is controlled by whoever owns the connecting address. |
Used by
LogonSessionLinuxtype: Linux O/S specific logon session information.
Example
Example
"LOCAL"