Analytics BIOC
Low
✕
Rare process created an SSH session to an uncommon cloud resource
A rare process created an SSH session to an uncommon cloud resource.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:
Attackers may use SSH or any similar utility as a Command and Control (C2) channel or to exfiltrate data to a remote host.
Investigative actions:
Investigate the actor process and its causality. Review the remote cloud asset, is it managed by the organization or a partner? Search for processes or files that were accessed by this SSH instance.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day