This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Program Executed Using Proxy/Local Command Via SSH.EXE
Original Source:
[Sigma source]
Title:
Program Executed Using Proxy/Local Command Via SSH.EXE
Status:
test
Description:
Detect usage of the "ssh.exe" binary as a proxy to launch other programs.
References:
-https://lolbas-project.github.io/lolbas/Binaries/Ssh/
-https://github.com/LOLBAS-Project/LOLBAS/pull/211/files
-https://gtfobins.github.io/gtfobins/ssh/
-https://man.openbsd.org/ssh_config#ProxyCommand
-https://man.openbsd.org/ssh_config#LocalCommand
Author:
frack113, Nasreddine Bencherchali
Date:
2022-12-29
modified:
2025-10-16
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage
:
'C:\Windows\System32\OpenSSH\sshd.exe'
selection_cli_img:
Image|endswith
:
'\ssh.exe'
Product
:
'OpenSSH for Windows'
- Hashes|contains
:
- 'IMPHASH=55b4964d29aad5438b9e950052dbbbc0'
- 'IMPHASH=334d66c33503ccbf647c15b47c27eef4'
- 'IMPHASH=27b0da080ef92afb37983d30d839141e'
- 'IMPHASH=977eb4c263d384e47daa0712d34713ab'
- 'IMPHASH=3eaadce9ae43d5a918bb082065815c3b'
- 'IMPHASH=980fe6cf0d996ab1eedf877222e722aa'
- 'IMPHASH=5f959422308ac3d721010d66647e100e'
- 'IMPHASH=a49aaa3d03d1cd9c8dc7fca60f7f480b'
- 'IMPHASH=dd335f759b6d5d6a8382b71dd9d65791'
selection_cli_flags:
CommandLine|contains
:
'ProxyCommand='
- CommandLine|contains|all
:
- 'PermitLocalCommand=yes'
- ' LocalCommand'
condition
:
selection_parent or all of selection_cli_*
Falsepositives:
-Legitimate usage for administration purposes
Level:
medium