Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕
Download CSV Show ATT&CK heatmapA process modified an SSH authorized_keys file Informational 3 variations
A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: SSH Authorized Keys (T1098.004)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Kubernetes - AGENT, Containers, Generic Persistence AnalyticsAttacker's goals: Adversaries use this to ensure that they possess the corresponding private key and may log in as an existing user via SSH.Investigative actions: Check the file modification, try to understand the impact of the related processes and network connections.Variations
A process modified an SSH authorized_keys2 file
Low overridden
A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. overridden
A process modified an SSH authorized_keys file from within a Kubernetes Pod
Low overridden
A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. overridden
Unpopular process modified the SSH authorized_keys file
Low overridden
An unpopular process modified the SSH authorized_keys file. overridden