Files
splunk-security_content/detections/endpoint/linux_possible_ssh_key_file_creation.yml
2022-07-27 10:29:47 -06:00

73 lines
2.5 KiB
YAML

name: Linux Possible Ssh Key File Creation
id: c04ef40c-72da-11ec-8eac-acde48001122
version: 1
date: '2022-01-11'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to look for possible ssh key file creation on ~/.ssh/
folder. This technique is commonly abused by threat actors and adversaries to gain
persistence and privilege escalation to the targeted host. by creating ssh private
and public key and passing the public key to the attacker server. threat actor can
access remotely the machine using openssh daemon service.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/.ssh*")
by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path
| `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`
| `linux_possible_ssh_key_file_creation_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the file name, file path, and process_guid executions from your endpoints.
If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
known_false_positives: Administrator or network operator can create file in ~/.ssh
folders for automation purposes. Please update the filter macros to remove false
positives.
references:
- https://www.hackingarticles.in/ssh-penetration-testing-port-22/
- https://attack.mitre.org/techniques/T1098/004/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
- Linux Living Off The Land
automated_detection_testing: passed
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 60
context:
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log
impact: 60
kill_chain_phases:
- Exploitation
message: A file $file_name$ is created in $file_path$ on $dest$
mitre_attack_id:
- T1098.004
- T1098
nist:
- DE.CM
observable:
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.dest
- Filesystem.file_create_time
- Filesystem.file_name
- Filesystem.process_guid
- Filesystem.file_path
risk_score: 36
security_domain: endpoint
asset_type: Endpoint