Sub-technique of T1021 Remote Services.View on attack.mitre.org
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
SSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user enables it. On ESXi, SSH can be enabled either directly on the host (e.g., via `vim-cmd hostsvc/enable_ssh`) or via vCenter. The SSH server can be configured to use standard password authentication or public-private keypairs in lieu of or in addition to a password. In this authentication scenario, the user’s public key must be in a special file on the computer running the server that lists which keypairs are allowed to login as that user (i.e., SSH Authorized Keys).
Rules on DetectionCode tagged with T1021.004.
| Rule | Level | Log source |
|---|---|---|
| Bitbucket Global SSH Settings Changed | medium | bitbucket / NULL |
| Bitbucket User Login Failure Via SSH | medium | bitbucket / NULL |
| OpenEDR Spawning Command Shell | medium | windows / process_creation |
| OpenSSH Server Listening On Socket | medium | windows / NULL |
| Port Forwarding Activity Via SSH.EXE | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco IOS XE Remote Access Probe Burst | Anomaly | NULL | Cisco IOS Logs |
| Cisco Privileged Account Creation with HTTP Command Execution | Correlation | NULL | |
| Cisco Privileged Account Creation with Suspicious SSH Activity | Correlation | NULL | |
| Cisco Secure Firewall - SSH Connection to Non-Standard Port | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - SSH Connection to sshd_operns | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| ESXi SSH Enabled | TTP | NULL | VMWare ESXi Syslog |
| Linux SSH Remote Services Script Execute | TTP | NULL | Sysmon for Linux EventID 1 |
| Windows Protocol Tunneling with Plink | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PuTTY Suite Utility Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| GroupAPT5 | APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| GroupBlackTech | BlackTech has used Putty for remote access. |
| GroupFIN13 | FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement. |
| GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| GroupFox Kitten | Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| GroupGCMAN | GCMAN uses Putty for lateral movement. |
| Used by | Procedure example |
|---|---|
| MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| ToolEmpire | Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection. |
| MalwareKinsing | Kinsing has used SSH for lateral movement. |
| MalwareQilin | Qilin can enable SSH access on ESXi hosts. |
| MalwarereGeorg | reGeorg can communicate using SSH through an HTTP tunnel. |
| Used by | Procedure example |
|---|---|
| CampaignC0032 | During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution. |
| CampaignCutting Edge | During Cutting Edge, threat actors used SSH for lateral movement. |
| CampaignLeviathan Australian Intrusions | Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.