BIOC
Informational
✕
SSH key pair discovery
Attackers may look for SSH key pairs using the find command.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Credential Access
- Status:
- Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Private Keys (T1552.004)
Indicator:
Process action type = execution AND target process name = find , cat AND target process cmd =~ .*(id_dsa|id_rsa|[.]key|[.]pgp|[.]gpg|[.]ppk|[.]p12|[.]pem|[.]pfx|[.]cer|[.]p7b|[.]asc).*
Preventable: yes