I always remap my sshd daemon to listen to a non-standard port, to reduce a lot of noise. Which has worked fine for years. But every now and then there are attempts. All the #Linux kernel flaws found lately has made remote login attempts more interesting for attackers. And they scan much more broadly now than just port 22. And that's why my second line of defence is to disallow remote root login - and also make use of the AllowGroups feature in sshd_config. Users granted remote access must be member of a specific group. And root is also excluded from this group. That pays off these days. And this is a nice filter match for #fail2ban and similar tools https://termbin.com/0cf6 I have 293 login attempts on "random users" since May 21. And 259 attempts as root. #infosec #ssh #sshd #systemhardening #kernel