Analytics BIOC Informational

Suspicious cloud compute instance SSH keys modification attempt

An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Persistence (TA0003) Lateral Movement (TA0008)
ATT&CK techniques: Account Manipulation: SSH Authorized Keys (T1098.004) Remote Services: Cloud Services (T1021.007) Remote Services: Direct Cloud VM Connections (T1021.008)
Detector tags: Cloud Lateral Movement Analytics
Attacker's goals:

Maintain persistence on a compromised compute instance. Escalate local privileges to gain root on compute instance.

Investigative actions:

Investigate if SSH keys were modified or added at the instance or project level. Investigate which permissions were obtained as a result of the SSH keys modification.

Test period:
N/A (single event)
Deduplication:
5 Days
7 variations:
  • Suspicious cloud compute instance SSH keys modification attempt by an identity with high administrative activity Informational
  • Instance SSH keys were modified for the first time in the cloud provider High (parent: Informational)
  • Suspicious cloud compute instance SSH keys modification by a service account Medium (parent: Informational)
  • Suspicious cloud compute instance SSH keys modification Informational
  • Suspicious GCP project level metadata modification by a service account Low (parent: Informational)
  • Suspicious GCP project level metadata modification Informational
  • Suspicious GCP project level metadata modification attempt Informational