Vendor: Linux

July 25, 2023 · View on GitHub

Product: SSH

Use-Case: Compromised Credentials

RulesModelsMITRE TTPsEvent TypesParsers
83411
Event TypeRulesModels
remote-logonT1078 - Valid Accounts
UA-UI-F: First activity from ISP
UA-UC-Suspicious: Activity from suspicious country
UA-UC-Two: Activity from two different countries
UA-UC-Three: Activity from 3 different countries

T1133 - External Remote Services
UA-UI-F: First activity from ISP
UA-UC-Suspicious: Activity from suspicious country
UA-UC-Two: Activity from two different countries
UA-UC-Three: Activity from 3 different countries

T1078.002 - T1078.002
SL-UH-I: Interactive logon using a service account
SL-UH-F: First access from asset for a service account
SL-UH-A: Abnormal access from asset for a service account

T1558 - Steal or Forge Kerberos Tickets
EXPERT-PENTEST-DOMAINS: Possible credentials theft attack detected
UA-UI-new: ISP of users during application activity
AL-UsH: Source hosts per User
IL-UH-SA: Interactive logon hosts for service accounts