OpenCanary SSH Login Attempt on Application Log Events

Alerts on recorded SSH login attempts from OpenCanary application logs (logtype 4002).

FreeUnreviewedSigmahighv1
title: OpenCanary SSH Login Attempt on Application Log Events
id: e9a95e69-8179-4ad3-a726-711136a23233
status: test
description: This rule flags when an OpenCanary node records an SSH login attempt in its application logs. Capturing these events matters because automated guessing or probing for access can indicate initial access or lateral movement activity toward reachable SSH services. The detection relies on the OpenCanary application log message type corresponding to login-attempt activity (logtype 4002).
references:
  - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
  - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_ssh_login_attempt.yml
author: Security Onion Solutions, Huntrule Team
date: 2024-03-08
tags:
  - attack.privilege-escalation
  - attack.initial-access
  - attack.lateral-movement
  - attack.persistence
  - attack.stealth
  - attack.t1133
  - attack.t1021
  - attack.t1078
logsource:
  category: application
  product: opencanary
detection:
  selection:
    logtype: 4002
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: ff7139bc-fdb1-4437-92f2-6afefe8884cb
    type: derived

What it detects

This rule flags when an OpenCanary node records an SSH login attempt in its application logs. Capturing these events matters because automated guessing or probing for access can indicate initial access or lateral movement activity toward reachable SSH services. The detection relies on the OpenCanary application log message type corresponding to login-attempt activity (logtype 4002).

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.