Analytics BIOC Low

Suspicious SSH Downgrade

The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs
ATT&CK tactics: Lateral Movement (TA0008) Defense Evasion (TA0005)
ATT&CK techniques: Remote Services (T1021) Impair Defenses: Downgrade Attack (T1562.010)
Detector tags: NDR Lateral Movement Analytics
Attacker's goals:

Attackers may attempt to move laterally over the network by exploiting problems in a lower version of SSH.

Investigative actions:

Audit the authentication attempts in the SSH server from the alerted host. If the source host authenticated to the SSH server, it may indicate that the attacker managed to connect to the remote host maliciously.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A Host Performed an SSH Downgrade For The First Time In The Last 30 Days Low
  • A Target Server Performed an SSH Downgrade For The First Time In The Last 30 Days Low