name: Linux Possible Ssh Key File Creation id: c04ef40c-72da-11ec-8eac-acde48001122 version: 1 date: '2022-01-11' author: Teoderick Contreras, Splunk type: Anomaly datamodel: - Endpoint description: This analytic is to look for possible ssh key file creation on ~/.ssh/ folder. This technique is commonly abused by threat actors and adversaries to gain persistence and privilege escalation to the targeted host. by creating ssh private and public key and passing the public key to the attacker server. threat actor can access remotely the machine using openssh daemon service. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/.ssh*") by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `linux_possible_ssh_key_file_creation_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. known_false_positives: Administrator or network operator can create file in ~/.ssh folders for automation purposes. Please update the filter macros to remove false positives. references: - https://www.hackingarticles.in/ssh-penetration-testing-port-22/ - https://attack.mitre.org/techniques/T1098/004/ tags: analytic_story: - Linux Privilege Escalation - Linux Persistence Techniques - Linux Living Off The Land automated_detection_testing: passed cis20: - CIS 3 - CIS 5 - CIS 16 confidence: 60 context: - Source:Endpoint - Stage:Privilege Escalation - Stage:Persistence dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log impact: 60 kill_chain_phases: - Exploitation message: A file $file_name$ is created in $file_path$ on $dest$ mitre_attack_id: - T1098.004 - T1098 nist: - DE.CM observable: - name: dest type: Hostname role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Filesystem.dest - Filesystem.file_create_time - Filesystem.file_name - Filesystem.process_guid - Filesystem.file_path risk_score: 36 security_domain: endpoint asset_type: Endpoint