โ† Library
splApache-2.0from splunk/security_content

Linux Possible Access Or Modification Of sshd Config File

The following analytic detects suspicious access or modification of the sshd_config file on Linux systems. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving processes like "cat," "nano," "vim," and "vi" accessing the sshd_config file. This activity is significant because unauthorized changes to sshd_config can allow threat actors to redirect port connections or use unauthorized keys, potentially compromising the system. If confirmed malicious, this could lead to unauthorized access, privilege escalation, or persistent backdoor access, posing a severe security risk.

Quality
67
FP risk
โ€”
Forks
0
Views
1
Rule source๐Ÿ”’ locked
๐Ÿ”’

Sign in to view the rule source

Free accounts can view the source for the top-ranked rules. Create one in seconds โ€” no credit card required.

Sign in โ†’
Linux Possible Access Or Modification Of sshd Config File ยท SPL rule | DetectionLint