Analytics BIOC Low

Rare process created an SSH session to an uncommon external host

Rare process created an SSH session to an uncommon external host.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:

Attackers may use SSH or any similar utility to as a Command and Control (C2) channel or to exfiltrate data to a remote host.

Investigative actions:

Investigate the actor process and its causality. Review the external IP/domain using known intelligence tools. Search for processes or files that were accessed by this SSH instance.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Rare process created an SSH session to a domain with an uncommon TLD Medium (parent: Low)
  • Rare process created an SSH session to an globally uncommon external host Low
  • Rare process created an SSH session to an external host Informational (parent: Low)