T1021.004 SSH
Sub-technique of T1021 Remote Services
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user. SSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Bitbucket Global SSH Settings Changedmediumtest · bitbucket
- Bitbucket User Login Failure Via SSHmediumtest · bitbucket
- OpenSSH Server Listening On Socketmediumtest · windows
- Port Forwarding Activity Via SSH.EXEmediumtest · windows
- OpenEDR Spawning Command Shellmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.