OpenCanary Application Logs: SSH Login Attempt on Monitoring Node

Alerts on recorded SSH login attempts from OpenCanary application logs (logtype 4002).

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags when an OpenCanary node reports an SSH service login attempt in its application telemetry. Such attempts may indicate automated probing, credential guessing, or tenant-to-tenant movement attempts against exposed services. Detection relies on OpenCanary application log events with a specific logtype value that corresponds to recorded SSH login attempts.

Related detections9 linkedT1078 — drag to rearrange
OpenCanary application logs: SSH new connection attempt on monitored node
OpenCanary Telnet Login Attempt Recorded in Application Logs
Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
SplashTop Network
OpenCanary Application Logs: SSH Login Attempt on Monitoring Node
Pivot detection · T1078 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.