Remote Service Session Hijacking: SSH Hijacking T1563.001
Tactic: Lateral Movement
Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote access on Linux and macOS systems. It allows a user to connect to another system via an encrypted tunnel, commonly authenticating through a password, certificate or the use of an asymmetric encryption key pair.
Authoring guide
These 10 rules share fields, values, and exclusions.
Fields filtered most (17 distinct)
These fields appear most often in rule filters.
Top indicator values (107 distinct)
These values appear most often in rule predicates.
Exclusions (145 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 10 rules
- Network Connection Initiated by Suspicious SSHD Child Process
- Potential Execution via SSH Backdoor
- Potential HackersChoice Tool Downloaded
- Potential THC Tool Downloaded
- Renaming of OpenSSH Binaries
- SSH Authorized Key File Activity Detected via Defend for Containers
- SSH Authorized Keys File Activity
- SSH Key Generated via ssh-keygen
- Unusual SSH Parent/Child Execution
- Unusual SSHD Child Process