Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1021.004

T1021.004SSH

T1021.004 — SSH is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 10 detection use cases covering it and 2 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (10)

Cisco IOS XE Remote Access Probe Burst ESCU actions · hunting P ESXi SSH Enabled ESCU actions · alerting P Linux SSH Remote Services Script Execute ESCU actions · alerting P Windows Protocol Tunneling with Plink ESCU actions · alerting P Windows PuTTY Suite Utility Execution ESCU actions · hunting P Cisco Privileged Account Creation with HTTP Command Execution ESCU actions · alerting P Cisco Privileged Account Creation with Suspicious SSH Activity ESCU actions · alerting P Cisco Secure Firewall - SSH Connection to Non-Standard Port ESCU actions · hunting P Cisco Secure Firewall - SSH Connection to sshd_operns ESCU actions · hunting P [LLM] Unauthenticated inbound SFTP to goshs followed by remote file operations Bespoke actions · hunting DSPDDCS

Articles citing this technique (2)