Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1572 ✕
Download CSV Show ATT&CK heatmapUncommon reverse SSH tunnel to external domain/ip Low 3 variations
An uncommon reverse SSH tunnel might have been created.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Protocol Tunneling (T1572)Required data: XDR AgentDetector tags: Abnormal Communication AnalyticsAttacker's goals: Attackers may use SSH to create an encrypted tunnel to allow an attacker to covertly connect to an internal host.Investigative actions: Review the external ip/domain. Investigate the causality of the process.Variations
Uncommon reverse SOCKS proxy SSH tunnel to external domain/ip
Medium overridden
An uncommon reverse SSH tunnel might have been created. overridden
Uncommon reverse SSH tunnel to external domain/ip to a sensitive port via a non-default bind port
Medium overridden
An uncommon reverse SSH tunnel might have been created. overridden
Uncommon reverse SSH tunnel to external domain/ip using a sensitive port
Low overridden
An uncommon reverse SSH tunnel might have been created. overridden