{"id":"T1021.004","name":"SSH","url":"https://attack.mitre.org/techniques/T1021/004","tactics":["lateral-movement"],"platforms":["ESXi","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0596","stix_id":"x-mitre-detection-strategy--5367273a-2f30-413e-a961-1dbd323be5b0","name":"Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution","url":"https://attack.mitre.org/detectionstrategies/DET0596","analytics":[{"id":"AN1638","stix_id":"x-mitre-analytic--bcc6bec5-63c7-4084-9d2f-da8b58d0f621","name":"Analytic 1638","description":"SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0596#AN1638","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"EXECVE","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"linux:syslog","channel":"None","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"linux-syslog"},{"name":"NSM:Flow","channel":"TCP port 22 traffic","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines correlation window from login to first post-SSH process (e.g., 60s)"},{"field":"SuspiciousProcessList","description":"List of binaries considered unusual in SSH context (e.g., nc, base64, bash -i)"},{"field":"UsernameFilter","description":"Accounts of interest for SSH logins (e.g., root, admin)"}],"live":true,"detection_strategies":["DET0596"],"techniques":["T1021.004"]},{"id":"AN1639","stix_id":"x-mitre-analytic--9c8ba5cd-40db-4214-8db1-b03b2d7b1690","name":"Analytic 1639","description":"SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0596#AN1639","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process = 'sshd'","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"process = 'ssh' OR eventMessage CONTAINS 'ssh'","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"TimeWindow","description":"Time range to correlate post-SSH activities (e.g., 45s)"},{"field":"UserContext","description":"Define authorized users to reduce false positives"},{"field":"CommandLineKeywords","description":"Suspicious terms like reverse shells, base64, curl"}],"live":true,"detection_strategies":["DET0596"],"techniques":["T1021.004"]},{"id":"AN1640","stix_id":"x-mitre-analytic--1b6eaec8-141f-44f8-ae1f-387c44635c38","name":"Analytic 1640","description":"SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas.","url":"https://attack.mitre.org/detectionstrategies/DET0596#AN1640","platforms":["ESXi"],"log_source_references":[{"name":"esxi:auth","channel":"None","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"esxi-auth"},{"name":"esxi:shell","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"esxi:vmkernel","channel":"port 22 access","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"AllowedUsers","description":"Legitimate SSH users to this host"},{"field":"TimeWindow","description":"Correlate SSH login and unauthorized commands or shell access"},{"field":"CommandList","description":"Flag commands like esxcli, rm, chmod post-login"}],"live":true,"detection_strategies":["DET0596"],"techniques":["T1021.004"]}],"live":true,"version":"1.0","techniques":["T1021.004"]}],"sigma_rules":[{"id":"16ab6143-510a-44e2-a615-bdb80b8317fc","title":"Bitbucket Global SSH Settings Changed","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects Bitbucket global SSH access configuration changes.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.lateral-movement","attack.defense-impairment","attack.t1685","attack.t1021.004"],"path":"rules/application/bitbucket/audit/bitbucket_audit_global_ssh_settings_change_detected.yml","techniques":["T1685","T1021.004"],"cves":[]},{"id":"327f48c1-a6db-4eb8-875a-f6981f1b0183","title":"Port Forwarding Activity Via SSH.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-12","modified":"2024-03-05","description":"Detects port forwarding activity via SSH.exe","references":["https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.lateral-movement","attack.t1572","attack.t1021.001","attack.t1021.004"],"path":"rules/windows/process_creation/proc_creation_win_ssh_port_forward.yml","techniques":["T1572","T1021.001","T1021.004"],"cves":[]},{"id":"3ce8e9a4-bc61-4c9b-8e69-d7e2492a8781","title":"OpenSSH Server Listening On Socket","author":"mdecrevoisier","status":"test","level":"medium","date":"2022-10-25","modified":null,"description":"Detects scenarios where an attacker enables the OpenSSH server and server starts to listening on SSH socket.","references":["https://github.com/mdecrevoisier/EVTX-to-MITRE-Attack/tree/master/TA0008-Lateral%20Movement/T1021.004-Remote%20Service%20SSH","https://winaero.com/enable-openssh-server-windows-10/","https://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse","https://virtualizationreview.com/articles/2020/05/21/ssh-server-on-windows-10.aspx","https://medium.com/threatpunter/detecting-adversary-tradecraft-with-image-load-event-logging-and-eql-8de93338c16"],"logsource":{"product":"windows","service":"openssh"},"tags":["attack.lateral-movement","attack.t1021.004"],"path":"rules/windows/builtin/openssh/win_sshd_openssh_server_listening_on_socket.yml","techniques":["T1021.004"],"cves":[]},{"id":"7f3a9c2d-4e8b-4a7f-9d3e-5c6f8a9b2e1d","title":"OpenEDR Spawning Command Shell","author":"@kostastsale","status":"experimental","level":"medium","date":"2026-02-19","modified":null,"description":"Detects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities.\nThis may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool.\nThreat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.\n","references":["https://kostas-ts.medium.com/detecting-abuse-of-openedrs-permissive-edr-trial-a-security-researcher-s-perspective-fc55bf53972c"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003","attack.lateral-movement","attack.t1021.004","attack.command-and-control","attack.t1219"],"path":"rules/windows/process_creation/proc_creation_win_comodo_ssh_shellhost_cmd_spawn.yml","techniques":["T1059.003","T1021.004","T1219"],"cves":[]},{"id":"d3f90469-fb05-42ce-b67d-0fded91bbef3","title":"Bitbucket User Login Failure Via SSH","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects SSH user login access failures.\nPlease note that this rule can be noisy and is recommended to use with correlation based on \"author.name\" field.\n","references":["https://confluence.atlassian.com/bitbucketserver/view-and-configure-the-audit-log-776640417.html","https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.lateral-movement","attack.credential-access","attack.t1021.004","attack.t1110"],"path":"rules/application/bitbucket/audit/bitbucket_audit_user_login_failure_via_ssh_detected.yml","techniques":["T1021.004","T1110"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-32433","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-39780","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}