sshd: Useless SSHD message without an user/ip and context.
Description
sshd: Useless SSHD message without an user/ip and context.
Query · wazuh
match="error: Could not get shadow information for NOUSER|" AND match="fatal: Read from socket failed: |error: ssh_msg_send: write|" AND match="^syslogin_perform_logout: |^pam_succeed_if(sshd:auth): error retrieving information about user|can't verify hostname: getaddrinfo"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=sshd -
match="error: Could not get shadow information for NOUSER|" AND match="fatal: Read from socket failed: |error: ssh_msg_send: write|" AND match="^syslogin_perform_logout: |^pam_succeed_if(sshd:auth): error retrieving information about user|can't verify hostname: getaddrinfo"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
5700