Suspicious PowerShell Enabling OpenSSH Server With Attacker Keys via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell commands that reference the sshd service together with an authorized_keys file which indicates an attacker enabling the built-in Windows OpenSSH server for remote access. The DeepSeek trojan used a base64 PowerShell script to start the SSH service and plant attacker public keys for persistent tunneling. Turning a host into an SSH server with foreign keys is a strong backdoor indicator.

Related detections9 linkedT1219 — drag to rearrange
Suspicious Curl Download to Update Executable during FortiClient EMS Exploitation
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
Malicious MeshCentral Agent Installation With Campaign Naming
Suspicious SimpleHelp Remote Access Tool Dropped In ProgramData Root
Suspicious MeshAgent Installation Arguments (via process_creation)
Possible AnyDesk Execution from Non-Standard Directory (via process_creation)
Suspicious MeshAgent Spawning Command Interpreter (via process_creation)
Suspicious AnyDesk Execution from Temporary or System Directory (via process_creation)
Suspicious AnyDesk Unattended Access Password Set via Command Line (via process_creation)
Suspicious PowerShell Enabling OpenSSH Server With Attacker Keys via process_creation
Pivot detection · T1219 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.