Detection rules › Splunk

ssh.exe Execution (Windows Event Log)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

ssh.exe is a legitimate SSH client included in Windows systems,providing secure shell access to remote servers. Due to its availability and capabilities, it can be exploited by attackers for covert communication, remote command execution, or tunneling, making it a potential tool for living-off-the-land attacks. This use case detects executions of ssh.exe

MITRE ATT&CK coverage

TacticTechniques
Stealth
Command & Control

References

Telemetry coverage

Rule body

id: '25328.46989'
title: ssh.exe Execution
description: 'ssh.exe is a legitimate SSH client included in Windows systems,providing
  secure shell access to remote servers. Due to its availability and capabilities,
  it can be exploited by attackers for covert communication, remote command execution,
  or tunneling, making it a potential tool for living-off-the-land attacks. This use
  case detects executions of ssh.exe. -- Threat Actor Association: APT28 (aka.Fancy
  Bear, Fighting Ursa, Forest Blizzard, Pawn Storm, TA422, STRONTIUM) -- Living Off
  the Land Binary and Scripts (LOLBAS) (LOLBIN)'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
  "<EventID>4688<" OR Type=Process) TERM(ssh) OR "ssh.exe" | where match(process_name,
  "(?i)^ssh\.exe")| table _time, host, user, process, process_*, parent_process_*
  | bin span=1s | stats values(*) as * by _time, host '
techniques:
- defense-evasion:indirect command execution
- command-and-control:protocol tunneling
technique_id: 
- T1202
- T1572
data_category:
- Windows event logs
references:
- https://lolbas-project.github.io/lolbas/Binaries/Ssh/

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<" OR Type=Process) TERM(ssh) OR "ssh.exe"

Stage 2: where

| where match(process_name, "(?i)^ssh\.exe")

Stage 3: table

| table _time, host, user, process, process_*, parent_process_*

Stage 4: bucket

| bin span=1s

Stage 5: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4688 corpus 317 (splunk 283, kusto 33, elastic 1)
field:"EventID" kind:eq value:"4688"
process_nameregex_match
  • "(?i)^ssh.exe" corpus 2 (splunk 2)
field:"process_name" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4688<"
1ssh
1"ssh.exe"