Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1021.004

T1021.004SSH

T1021.004 — SSH is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 13 detection use cases covering it and 4 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (13)

Cisco IOS XE Remote Access Probe Burst ESCU actions · hunting P ESXi SSH Enabled ESCU actions · alerting P Linux SSH Remote Services Script Execute ESCU actions · alerting P Windows Protocol Tunneling with Plink ESCU actions · alerting P Windows PuTTY Suite Utility Execution ESCU actions · hunting P Cisco Privileged Account Creation with HTTP Command Execution ESCU actions · alerting P Cisco Privileged Account Creation with Suspicious SSH Activity ESCU actions · alerting P Cisco Secure Firewall - SSH Connection to Non-Standard Port ESCU actions · hunting P Cisco Secure Firewall - SSH Connection to sshd_operns ESCU actions · hunting P [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] goshs process accepting inbound SFTP/SSH connections (exposed file server) Bespoke delivery · hunting DSPDDCS [LLM] Compromised device Telnet/SSH weak-password worm fan-out Bespoke delivery · alerting DSPDDCS [LLM] HelloNet renamed-PuTTY reverse SSH tunnel to 5.39.253.206 Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (4)