{"id":"T1563.001","name":"SSH Hijacking","url":"https://attack.mitre.org/techniques/T1563/001","tactics":["lateral-movement"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0256","stix_id":"x-mitre-detection-strategy--bdbd724e-b3e2-44d7-a9d6-ba2a4915762c","name":"Detection Strategy for SSH Session Hijacking","url":"https://attack.mitre.org/detectionstrategies/DET0256","analytics":[{"id":"AN0710","stix_id":"x-mitre-analytic--3517708a-f80e-4335-a122-65b9b3505e8d","name":"Analytic 0710","description":"Suspicious reuse of SSH agent sockets across multiple users or processes, anomalous access to ~/.ssh/ or /tmp/ssh-* sockets, and abnormal patterns of lateral movement via SSH without new authentication events. Defender view: detect when one process accesses another user's SSH agent or when an existing SSH connection is used to pivot unexpectedly.","url":"https://attack.mitre.org/detectionstrategies/DET0256#AN0710","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open or connect syscalls on /tmp/ssh-* or $SSH_AUTH_SOCK","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"Execution of ssh/scp/sftp without corresponding authentication log","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"NSM:Connections","channel":"Missing new login event but session activity continues","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"UserContext","description":"Tune alerts for cross-user access to SSH agent sockets."},{"field":"TimeWindow","description":"Correlate lack of authentication with lateral SSH activity within a short timeframe."}],"live":true,"detection_strategies":["DET0256"],"techniques":["T1563.001"]},{"id":"AN0711","stix_id":"x-mitre-analytic--de71bbc0-66b2-41ae-a3f3-4911ac31b391","name":"Analytic 0711","description":"Unusual access to SSH agent sockets in /tmp/ or /private/tmp, process access to another user’s $SSH_AUTH_SOCK, and lateral SSH activity without corresponding login events. Defender view: correlation of socket access with anomalous network flows to internal systems.","url":"https://attack.mitre.org/detectionstrategies/DET0256#AN0711","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process opening SSH_AUTH_SOCK or /tmp/ssh-* socket not owned by same UID","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of ssh or sftp without corresponding login event","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Session reuse without new auth event","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"SocketPathScope","description":"Limit detection to monitored SSH agent socket directories."},{"field":"BaselineUsers","description":"Establish normal SSH agent ownership and expected usage for tuning."}],"live":true,"detection_strategies":["DET0256"],"techniques":["T1563.001"]}],"live":true,"version":"1.0","techniques":["T1563.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}