OpenSSH

5 events across 3 channels

Event IDTitleChannel
1%1: %2.Admin
2%1: %2.Admin
3%1: %2.Operational
4%1: %2.Operational
6%1: %2.Debug

Event ID 1 — %1: %2.

Provider
OpenSSH
Channel
Admin

Message

%1: %2

Fields

NameDescription
process
payload

Event ID 2 — %1: %2.

Provider
OpenSSH
Channel
Admin
Level
2
Samples
1

Message

%1: %2

Fields

NameDescription
process
payload

Example Event

system:
  provider: OpenSSH
  guid: C4B57D35-0636-4BC3-A262-370F249F9802
  event_source_name: ''
  event_id: 2
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2023-10-25T22:48:38.752876+00:00'
  event_record_id: 8
  correlation: {}
  execution:
    process_id: 2320
    thread_id: 1048
  channel: OpenSSH/Admin
  computer: WinDevEval
  security:
    user_id: S-1-5-18
event_data:
  process: sshd
  payload: 'error: kex_exchange_identification: Connection closed by remote host'
message: ''

References

Event ID 3 — %1: %2.

Provider
OpenSSH
Channel
Operational

Message

%1: %2

Fields

NameDescription
process
payload

Event ID 4 — %1: %2.

Provider
OpenSSH
Channel
Operational
Level
4
Samples
1

Message

%1: %2

Fields

NameDescription
process
payload

Example Event

system:
  provider: OpenSSH
  guid: C4B57D35-0636-4BC3-A262-370F249F9802
  event_source_name: ''
  event_id: 4
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-10-25T22:56:14.223049+00:00'
  event_record_id: 40
  correlation: {}
  execution:
    process_id: 3136
    thread_id: 3384
  channel: OpenSSH/Operational
  computer: WinDevEval
  security:
    user_id: S-1-5-18
event_data:
  process: sshd
  payload: Received signal 8; terminating.
message: ''

Sigma Rules

References

Event ID 6 — %1: %2.

Provider
OpenSSH
Channel
Debug

Message

%1: %2

Fields

NameDescription
process
payload