typos as an indicator of hands on keyboard

0001-01-01

Observing typos within command histories is a good indicator of hands-on-keyboard activity. Serious automation scripts will typically have typos in commands removed, as they do not work and throw errors. Humans naturally make typos from time to time, so typos in command lines are a good indicator that a human typed it rather than automated/worming malware.


No notes link to this note