Aspects described herein may allow keystroke logs to be monitored. A computing device may receive a plurality of keystroke logs and provide, to a machine learning model, the plurality of keystroke logs. The computing device may receive, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a computing system. The computing device may retrieve, from a database, one or more change orders, each indicating an authorization to change the computing system. The computing device may send, to a second computing device and based on determining that the first command does not match the one or more change orders, an alert indicating the first keystroke log. In this way, unauthorized change to the computing system may be detected.
Full Text
What is claimed is: