Linux SSHD Logs: Suspicious OpenSSH Daemon Error Messages

Alerts on sshd log entries with specific OpenSSH fatal or cryptographic error messages indicating suspicious access attempts.

FreeUnreviewedSigmamediumv1
title: "Linux SSHD Logs: Suspicious OpenSSH Daemon Error Messages"
id: 5da0b54b-aeeb-4533-8fb7-0de546bea155
status: test
description: This rule flags specific OpenSSH sshd error strings that indicate fatal or otherwise suspicious processing failures. Attackers may trigger these messages through malformed inputs, unsupported cryptographic parameters, or invalid keys/certificates to probe or exploit weaknesses. The detection relies on Linux sshd service log telemetry containing the exact error keywords listed by the rule.
references:
  - https://github.com/openssh/openssh-portable/blob/c483a5c0fb8e8b8915fad85c5f6113386a4341ca/ssherr.c
  - https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/sshd_rules.xml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/builtin/sshd/lnx_sshd_susp_ssh.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-06-30
modified: 2021-11-27
tags:
  - attack.initial-access
  - attack.t1190
logsource:
  product: linux
  service: sshd
detection:
  keywords:
    - unexpected internal error
    - unknown or unsupported key type
    - invalid certificate signing key
    - invalid elliptic curve value
    - incorrect signature
    - error in libcrypto
    - unexpected bytes remain after decoding
    - "fatal: buffer_get_string: bad string"
    - "Local: crc32 compensation attack"
    - bad client public DH value
    - Corrupted MAC on input
  condition: keywords
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: e76b413a-83d0-4b94-8e4c-85db4a5b8bdc
    type: derived

What it detects

This rule flags specific OpenSSH sshd error strings that indicate fatal or otherwise suspicious processing failures. Attackers may trigger these messages through malformed inputs, unsupported cryptographic parameters, or invalid keys/certificates to probe or exploit weaknesses. The detection relies on Linux sshd service log telemetry containing the exact error keywords listed by the rule.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.