Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • A process modified an SSH authorized_keys file Informational 3 variations

    A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: SSH Authorized Keys (T1098.004)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Kubernetes - AGENT, Containers, Generic Persistence Analytics
    Attacker's goals: Adversaries use this to ensure that they possess the corresponding private key and may log in as an existing user via SSH.
    Investigative actions: Check the file modification, try to understand the impact of the related processes and network connections.

    Variations

    A process modified an SSH authorized_keys2 file

    Low overridden

    A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. overridden

    A process modified an SSH authorized_keys file from within a Kubernetes Pod

    Low overridden

    A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. overridden

    Unpopular process modified the SSH authorized_keys file

    Low overridden

    An unpopular process modified the SSH authorized_keys file. overridden