Remote Service Session Hijacking: SSH Hijacking T1563.001

Tactic: Lateral Movement

Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote access on Linux and macOS systems. It allows a user to connect to another system via an encrypted tunnel, commonly authenticating through a password, certificate or the use of an asymmetric encryption key pair.

Authoring guide

These 10 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type9eq 7, in 2start, change, creation
EventType7eq 4, in 3exec, ProcessRollup2, connection_attempted, creation, end
host.os.type7eq 7
process_name5in 3, eq 1, is_not_null 1, wildcard 1curl, wget, *.elf, *.lua*, *.php*
Image3eq 1, starts_with 1, wildcard 1./, ./*, /boot/, /boot/*, /dev/shm/
event.category3eq 3file, process
file.name3in 2, eq 1authorized_keys, authorized_keys2, libkeyutils.so
parent_process_name3eq 2, in 1sshd, ssh
CommandLine2contains 1, eq 1/usr/sbin/sshd -D -R, github.com/hackerschoice/, gsocket.io/, nossl.segfault.net/
TargetFilename2in 1, wildcard 1/etc/ssh/*, /home/*/.ssh/*, /root/.ssh/*, /usr/bin/scp, /usr/bin/sftp
process.args2eq 1, starts_with 1-c, http://nossl.segfault.net/, https://github.com/hackerschoice/, https://gsocket.io/
process.args_count2eq 21, 2
ParentCommandLine1eq 1/usr/sbin/sshd -D -R, sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups
ParentImage1eq 1/usr/sbin/sshd
container.id1wildcard 1*

Top indicator values (107 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
61087
EventTypeeq
exec
4579
EventTypeeq
connection_attempted
175
EventTypeeq
end
119
EventTypein
exec
2206
EventTypein
ProcessRollup2
1118
EventTypein
creation
134
EventTypein
exec_event
1150
EventTypein
executed
198
EventTypein
file_create_event
19
EventTypein
process_started
183
EventTypein
processrollup2
19
EventTypein
start
1168
event.categoryeq
file
243
event.typein
change
220
event.typein
creation
219
file.namein
authorized_keys
23
file.namein
authorized_keys2
23
parent_process_nameeq
sshd
23
process_namein
curl
290
process_namein
wget
247
CommandLinecontains
github.com/hackerschoice/
1
CommandLinecontains
gsocket.io/
1
CommandLinecontains
nossl.segfault.net/
1
CommandLinecontains
thc.org/
1
CommandLineeq
/usr/sbin/sshd -D -R
1
Imageeq
/usr/bin/ssh-keygen
1
Imagestarts_with
./
126
Imagestarts_with
/boot/
128
Imagestarts_with
/dev/shm/
153

Exclusions (145 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinecontains
ansible
1
CommandLinecontains
become-success
1
CommandLineeq
true
1
CommandLinein
-bash
1
CommandLinein
-sh
1
CommandLinein
-zsh
1
CommandLinewildcard
*BECOME-SUCCESS*
1
CommandLinewildcard
*ansible*
1
CommandLinewildcard
sh -c -- /usr/bin/env -i PATH=*
1
CommandLinewildcard
sh -c /usr/bin/env -i PATH=*
1
Imageeq
/home/sa-ansible
1
Imageeq
/library/developer/commandlinetools/usr/bin/git
1
Imageeq
/opt/jc/bin/jumpcloud-agent
1
Imageeq
/opt/puppetlabs/puppet/bin/puppet
1
Imageeq
/usr/bin/bsdtar
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 10 rules