Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1098.004

T1098.004SSH Authorized Keys

T1098.004 — SSH Authorized Keys is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 13 detection use cases covering it and 5 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
5Articles
0Sub-techniques
2Tactics

Use cases covering this technique (13)

GitHub SSH key added from suspicious IP Internal install · alerting DD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS Linux Auditd Possible Access Or Modification Of Sshd Config File ESCU actions · hunting P Linux Possible Access Or Modification Of sshd Config File ESCU actions · hunting P Linux Possible Ssh Key File Creation ESCU actions · hunting P Linux SSH Authorized Keys Modification ESCU actions · hunting P [LLM] redis-server writes to persistence paths (cron / SSH authorized_keys / systemd) Bespoke install · alerting DSΣPCS [LLM] SSH authorized_keys written by non-SSH tooling (symlink repo payload) Bespoke install · hunting DSΣPDDCS [LLM] Node archive-extraction process writing to Linux persistence paths (decompress dir-escape) Bespoke install · hunting DSΣDDCS [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] FTP client / Hive (commons-net) overwrites Unix auth files via path-traversal LIST (CVE-2018-1315) Bespoke actions · alerting DSΣPCS [LLM] FTP control-channel connection followed by write to Unix system path (CVE-2018-1315 traversal chain) Bespoke exploit · hunting DSPCS

Articles citing this technique (5)