{"id":"d3f90469-fb05-42ce-b67d-0fded91bbef3","title":"Bitbucket User Login Failure Via SSH","description":"Detects SSH user login access failures.\nPlease note that this rule can be noisy and is recommended to use with correlation based on \"author.name\" field.\n","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":"","tags":["attack.lateral-movement","attack.credential-access","attack.t1021.004","attack.t1110"],"technique_ids":["T1021.004","T1110"],"logsource":{"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."},"falsepositives":["Legitimate user wrong password attempts."],"references":["https://confluence.atlassian.com/bitbucketserver/view-and-configure-the-audit-log-776640417.html","https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html"],"source_path":"rules/application/bitbucket/audit/bitbucket_audit_user_login_failure_via_ssh_detected.yml","source_sha256":"3ba6488a1c73a35580d58210685d5094da88da0f52a4d0c58c10856998ecc1ed","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/bitbucket/audit/bitbucket_audit_user_login_failure_via_ssh_detected.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Bitbucket User Login Failure Via SSH\nid: d3f90469-fb05-42ce-b67d-0fded91bbef3\nstatus: test\ndescription: |\n    Detects SSH user login access failures.\n    Please note that this rule can be noisy and is recommended to use with correlation based on \"author.name\" field.\nreferences:\n    - https://confluence.atlassian.com/bitbucketserver/view-and-configure-the-audit-log-776640417.html\n    - https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html\nauthor: Muhammad Faisal (@faisalusuf)\ndate: 2024-02-25\ntags:\n    - attack.lateral-movement\n    - attack.credential-access\n    - attack.t1021.004\n    - attack.t1110\nlogsource:\n    product: bitbucket\n    service: audit\n    definition: 'Requirements: \"Advance\" log level is required to receive these audit events.'\ndetection:\n    selection:\n        auditType.category: 'Authentication'\n        auditType.action: 'User login failed(SSH)'\n    condition: selection\nfalsepositives:\n    - Legitimate user wrong password attempts.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1021.004","id":"T1021.004","name":"SSH","page":"techniques/enterprise/T1021.004/"},{"key":"enterprise/T1110","id":"T1110","name":"Brute Force","page":"techniques/enterprise/T1110/"}],"data_path":"data/detection-rules/d3f90469-fb05-42ce-b67d-0fded91bbef3.json","kind":"sigma"}
