OSQuery Detected SSH Listener


Description

Check if SSH is listening in a non-production environment. This could be an indicator of persistent access within an environment.

Query · python

def rule(event):
    return (
        event.get("name") == "pack_incident-response_listening_ports"
        and event.deep_get("columns", "port") == "22"
        and event.get("action") == "added"
    )

Analyst notes

Terminate the SSH daemon, investigate for signs of compromise.

Raw source OSQuery Detected SSH Listener · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: osquery_ssh_listener.py
RuleID: "Osquery.SSHListener"
DisplayName: "OSQuery Detected SSH Listener"
Enabled: true
LogTypes:
  - Osquery.Differential
Tags:
  - Osquery
  - Lateral Movement:Remote Services
Reports:
  MITRE ATT&CK:
    - TA0008:T1021
Severity: Medium
Description: >
  Check if SSH is listening in a non-production environment. This could be an indicator of persistent access within an environment.
Runbook: >
  Terminate the SSH daemon, investigate for signs of compromise.
Reference: https://medium.com/uptycs/osquery-what-it-is-how-it-works-and-how-to-use-it-ce4e81e60dfc
SummaryAttributes:
  - action
  - hostIdentifier
  - name
Tests:
  - Name: SSH Listener Detected
    ExpectedResult: true
    Log:
      {
        "action": "added",
        "calendarTime": "Tue Sep 11 16:14:21 2018 UTC",
        "columns":
          {
            "build_distro": "10.12",
            "build_platform": "darwin",
            "config_hash": "1111",
            "config_valid": "1",
            "counter": "14",
            "global_state": "0",
            "extensions": "active",
            "instance_id": "1111",
            "pid": "223",
            "port": "22",
            "resident_size": "54894592",
            "start_time": "1536634519",
            "system_time": "12472",
            "user_time": "31800",
            "uuid": "37821E12-CC8A-5AA3-A90C-FAB28A5BF8F9",
            "version": "Not Supported",
            "watcher": "92",
          },
        "counter": "255",
        "decorations": { "host_uuid": "1111", "environment": "corp" },
        "epoch": "0",
        "hostIdentifier": "test.lan",
        "log_type": "result",
        "name": "pack_incident-response_listening_ports",
        "unixTime": "1536682461",
      }
  - Name: SSH Listener Not Detected
    ExpectedResult: false
    Log:
      {
        "action": "added",
        "calendarTime": "Tue Sep 11 16:14:21 2018 UTC",
        "columns":
          {
            "build_distro": "10.12",
            "build_platform": "darwin",
            "config_hash": "1111",
            "config_valid": "1",
            "counter": "14",
            "global_state": "2",
            "extensions": "active",
            "instance_id": "1111",
            "pid": "223",
            "port": "443",
            "resident_size": "54894592",
            "start_time": "1536634519",
            "system_time": "12472",
            "user_time": "31800",
            "uuid": "37821E12-CC8A-5AA3-A90C-FAB28A5BF8F9",
            "version": "10.14.2",
            "watcher": "92",
          },
        "counter": "255",
        "decorations": { "host_uuid": "1111", "environment": "corp" },
        "epoch": "0",
        "hostIdentifier": "test.lan",
        "log_type": "result",
        "name": "pack_incident-response_listening_ports",
        "unixTime": "1536682461",
      }


# ------ paired body: osquery_ssh_listener.py ------

def rule(event):
    return (
        event.get("name") == "pack_incident-response_listening_ports"
        and event.deep_get("columns", "port") == "22"
        and event.get("action") == "added"
    )

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.