OpenSSH Server (sshd) Listening on SSH Socket on Windows

Flags OpenSSH (sshd) events showing the SSH server has started listening on a socket.

FreeReviewedSigma · Medium · v2
Product
windows
Service
openssh
Author
mdecrevoisier (SigmaHQ), DRL 1.1
Published
2022-10-25
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies when the OpenSSH server process (sshd) emits an event indicating it has begun listening on an SSH socket. Attackers may enable or start an SSH service to establish remote access, so the listener state is a key indicator of new network-facing exposure. Detection relies on Windows OpenSSH service telemetry with Event ID 4 and an ssld log payload that starts with the exact listening message.

Related detections9 linkedT1021.004 — drag to rearrange
Malicious Bad Apples Remote Apple Events Lateral Movement via osascript
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
OpenSSH Server (sshd) Listening on SSH Socket on Windows
Pivot detection · T1021.004 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.