Analytics BIOC Informational

Unusual SSH activity that resembles SSH proxy

A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Proxy: Internal Proxy (T1090.001)
Attacker's goals:

Attackers aim to establish a covert command and control channel or relay communications through a compromised SSH connection.

Investigative actions:

Review the SSH connections to identify any unusual proxy activity or traffic patterns. Investigate the user accounts involved in the SSH connections to determine if credentials were compromised. Additionally, examine logs for any unexpected data transfers or commands that may indicate malicious intent.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • High Volume Unusual SSH activity that resembles SSH proxy Low (parent: Informational)
  • Suspicious SSH activity that resembles SSH proxy Low (parent: Informational)
  • Unusual SSH activity that resembles SSH proxy detected Low (parent: Informational)