Analytics BIOC Low

Uncommon SSH session was established

An uncommon SSH session was established.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
Detector tags: NDR Lateral Movement Analytics
Attacker's goals:

Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.

Investigative actions:

Review the external IP/domain using known intelligence tools. Investigate the causality of the process and its user ID to find uncommon behaviors. Search for processes or files that were created by this SSH instance.

Test period:
N/A (single event)
Deduplication:
1 Day
14 variations:
  • An Uncommon SSH session was established using a rare server HASSH for the ssh server Low
  • An Uncommon SSH session was established using a rare client HASSH for the agent Low
  • An Uncommon SSH session was established using a rare request banner for the agent Low
  • An Uncommon SSH session was established using a rare Response banner for the ssh server Low
  • An Uncommon SSH session was established using a rare Response banner Low
  • An Uncommon SSH session was established using a rare request banner Low
  • An Uncommon SSH session was established using a rare Client HASSH Low
  • An Uncommon SSH session was established using a rare Server HASSH Low
  • A suspicious SSH session was established Low
  • An Uncommon SSH session was established to a rare IP address Low
  • An Uncommon SSH session was established using a nonstandard SSH port Low
  • Uncommon SSH session was established to a rare internal IP Low
  • Uncommon SSH session was established that involved a higher than usual volume Low
  • Uncommon SSH session was established to an internal IP Informational (parent: Low)