1200KM / detection
T1021.004 SSH — Detection Rules
Detection workspace for T1021.004 SSH: 5 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitbucket Global SSH Settings Changed · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- Bitbucket User Login Failure Via SSH · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- OpenSSH Server Listening On Socket · test · medium · {"product":"windows","service":"openssh"}
- OpenEDR Spawning Command Shell · experimental · medium · {"product":"windows","category":"process_creation"}
- Port Forwarding Activity Via SSH.EXE · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1021.004 SSH
MATCH(successful_ssh_login) AND source_host NOT_IN approved_ssh_sources -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0596 Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution
AN1638 Analytic 1638
SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior.
AN1639 Analytic 1639
SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns.
AN1640 Analytic 1640
SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Lazarus Group · G0032
- GCMAN · G0036
- menuPass · G0045
- FIN7 · G0046
- OilRig · G0049
- Leviathan · G0065
- APT39 · G0087
- BlackTech · G0098
- Rocke · G0106
- Fox Kitten · G0117
- Indrik Spider · G0119
- TeamTNT · G0139
- Aquatic Panda · G0143
- Scattered Spider · G1015
- FIN13 · G1016
- APT5 · G1023
- Salt Typhoon · G1045
- Storm-1811 · G1046
- UNC3886 · G1048
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.