Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

← Amenazas
Técnica MITRE ATT&CK · Persistencia, Escalada de privilegios

T1098.004 SSH Authorized Keys

Subtécnica de T1098 Account Manipulation

Adversaries may modify the SSH authorized_keys file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The authorized_keys file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured.…

Ficha en MITRE ATT&CK ↗

Quién la usa · con noticias en Jábega

Reglas Sigma para cazarla

SigmaHQ no tiene reglas para esta técnica.

Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.