Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process

Rule Info

Name
Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
Author
Arnim Rupp, Nasreddine Bencherchali, Thomas Patzke
Description
Detects potentially suspicious child process of SSH process (sshd) with a specific execution user. This could be a sign of potential exploitation of CVE-2024-3094.
Date
2024-04-01 00:00:00
Modified
None
Id
9aa27839-e8ba-4d7a-ac1a-746c22c3d1e5
Tags
attack.execution cve.2024.3094 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Arnim Rupp
Merge PR #4794 from @ruppde - Potential Exploitation of CVE-2024-3094
2024-04-02