{"id":"e76b413a-83d0-4b94-8e4c-85db4a5b8bdc","title":"Suspicious OpenSSH Daemon Error","description":"Detects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-06-30","modified":"2021-11-27","tags":["attack.initial-access","attack.t1190"],"technique_ids":["T1190"],"logsource":{"product":"linux","service":"sshd"},"falsepositives":["Unknown"],"references":["https://github.com/openssh/openssh-portable/blob/c483a5c0fb8e8b8915fad85c5f6113386a4341ca/ssherr.c","https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/sshd_rules.xml"],"source_path":"rules/linux/builtin/sshd/lnx_sshd_susp_ssh.yml","source_sha256":"8e0302ef07eabcb04ee3d63ffcedce173270ca20e6b6213c83a3d7db8630ce9e","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/builtin/sshd/lnx_sshd_susp_ssh.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious OpenSSH Daemon Error\nid: e76b413a-83d0-4b94-8e4c-85db4a5b8bdc\nstatus: test\ndescription: Detects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts\nreferences:\n    - https://github.com/openssh/openssh-portable/blob/c483a5c0fb8e8b8915fad85c5f6113386a4341ca/ssherr.c\n    - https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/sshd_rules.xml\nauthor: Florian Roth (Nextron Systems)\ndate: 2017-06-30\nmodified: 2021-11-27\ntags:\n    - attack.initial-access\n    - attack.t1190\nlogsource:\n    product: linux\n    service: sshd\ndetection:\n    keywords:\n        - 'unexpected internal error'\n        - 'unknown or unsupported key type'\n        - 'invalid certificate signing key'\n        - 'invalid elliptic curve value'\n        - 'incorrect signature'\n        - 'error in libcrypto'\n        - 'unexpected bytes remain after decoding'\n        - 'fatal: buffer_get_string: bad string'\n        - 'Local: crc32 compensation attack'\n        - 'bad client public DH value'\n        - 'Corrupted MAC on input'\n    condition: keywords\nfalsepositives:\n    - Unknown\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1190","id":"T1190","name":"Exploit Public-Facing Application","page":"techniques/enterprise/T1190/"}],"data_path":"data/detection-rules/e76b413a-83d0-4b94-8e4c-85db4a5b8bdc.json","kind":"sigma"}
