A process modified an SSH authorized_keys file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Kubernetes - AGENT, Containers, Generic Persistence Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: SSH Authorized Keys (T1098.004)
Severity
Informational
Description
A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host.
Attacker's Goals
Adversaries use this to ensure that they possess the corresponding private key and may log in as an existing user via SSH.
Investigative actions
Check the file modification, try to understand the impact of the related processes and network connections.
Variations
Was this helpful?
