Link Search Menu Expand Document

SSH_Root_Login_Accepted_Internal

ID: 100481

Description:

A behavior rule to track occurrences of SSH successful login, by hostname, as Alert_Policy events.

This rule also indicates the (first/new) occurrence of SSH login attempts on a particular machine, for the root user from an internal IP address (HOME_NET). This rule also tracks the first time a particular hostname or authentication method is used.

Notes:

  • Corresponding rule SSH_Root_Login_Accepted_External to track external root SSH login

Repository: Group: SSHD Type: event

Default Status:

Enabled

Tags:
 

Selector:

Query:

Filters:

Field MUST hit
@event_type @sshd
@sshd.result accepted
@sshd.user root
@sshd.sip entity: [ HOME_NET ]
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@source asset account login

Risks:

Risks Base Score Dimension
ALERT_POLICY 200 alert

Attributes:

Alias Key
IP @sshd.sip
Country @sshd._ip.country
City @sshd._ip.city
Organization @sshd._ip.org
ISP @sshd._ip.isp
Username @sshd.user
Method @sshd.method
Stream @stream
Server @source

Correlation Rules:

First Occurrence:

Name Window Fields
NewServer 20 days @source
  Risks: ML_NEW_ASSET
NewMethod 20 days @sshd.method
  Risks: ML_NEW_APP

History:

User Date
ho*d@fluencysecurity.com 2021 Nov 29 11:45:40 EST
ho*d@fluencysecurity.com 2021 Nov 29 11:47:29 EST

This page was automatically created/formatted on Wed, 2022 May 4 21:43:53 EDT, from rule_dump.json (4d88bffdfb1cea26b3985f2193033606)