A small toolkit for detecting suspicious patterns in SSH authentication logs — brute-force attempts, off-hours logins, and successful logins that follow a burst of failures. Implemented in both Python ...