Link Search Menu Expand Document

SSH_Login_Failed

ID: 100468

Description:

A behavior rule to track first occurrence of SSH failed login, by asset (hostname).

This rule indicates the (first) occurrence of failed SSH login attempts on a particular machine. This rule also tracks the first time a particular authentication method is used. This indicates presence of a functional SSH Server on the network.

Notes: Corresponding rule SSH Login Accepted tracks successful login

Repository: Group: SSHD Type: event

Default Status:

Enabled

Tags:  
SSH SSHD
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @sshd
@sshd.result failed
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@source asset account login

Risks:

Risks Base Score Dimension
     

Attributes:

Alias Key
IP @sshd.sip
Country @sshd._ip.country
City @sshd._ip.city
Organization @sshd._ip.org
ISP @sshd._ip.isp
Username @sshd.user
Method @sshd.method
Server @source
Stream @stream

Correlation Rules:

First Occurrence:

Name Window Fields
NewServer 30 days @source
  Risks: ML_NEW_ASSET
NewMethod 20 days @sshd.method
  Risks: ML_NEW_APP

History:

User Date
ho*d@fluencysecurity.com 2021 Oct 6 17:44:16 EDT
ho*d@fluencysecurity.com 2021 Oct 6 17:44:44 EDT
ho*d@fluencysecurity.com 2021 Oct 6 17:47:52 EDT
ho*d@fluencysecurity.com 2021 Oct 6 18:06:55 EDT
ho*d@fluencysecurity.com 2021 Oct 7 11:07:18 EDT
ho*d@fluencysecurity.com 2021 Oct 7 12:18:15 EDT

This page was automatically created/formatted on Wed, 2022 May 4 21:43:53 EDT, from rule_dump.json (4d88bffdfb1cea26b3985f2193033606)