 
    
    
    Rule Info
Name
                    
                    
                        Shell Invocation Via Ssh - Linux
                    
                
            Author
                    
                    
                        Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
                    
                
            Description
                    
                    
                        Detects the use of the "ssh" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
                    
                
            Reference
                    
                    
                        
                    
                
            Date
                    
                    
                        2024-08-29 00:00:00
                    
                
            Modified
                    
                    
                        None
                    
                
            Id
                    
                    
                        8737b7f6-8df3-4bb7-b1da-06019b99b687
                    
                
            Tags
                    
                    
                        attack.execution attack.t1059
                    
                
            Type
                Community Rule
            Link to Public Repo
                
            