Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-05-21
Updated
2026-08-28

ATT&CK techniques

Cred Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects use of sshpass to supply an SSH password on the command line, the method ShinyHunters used for credential spraying across PeopleSoft nodes listed in /etc/hosts during the education sector campaign. Adversaries rely on sshpass to automate password-based lateral movement, and passing credentials inline is rarely legitimate in enterprise environments, so this behavior deserves scrutiny.

Related detections9 linkedT1021.004 — drag to rearrange
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Suspicious Bruteforce via Password Reset (via security)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Bitbucket Audit: Global SSH Settings Changed
Bitbucket Audit: SSH User Login Failures
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Pivot detection · T1021.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.