Rule Info
Name
Shell Invocation Via Ssh - Linux
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects the use of the "ssh" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Reference
Date
2024-08-29 00:00:00
Modified
None
Id
8737b7f6-8df3-4bb7-b1da-06019b99b687
Tags
attack.execution attack.t1059 DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit