Windows: ssh.exe Used as Proxy/Local Command Launcher via ProxyCommand and LocalCommand
Detects Windows executions of ssh.exe that use ProxyCommand and PermitLocalCommand/LocalCommand to launch proxied or local commands.
- Product
- windows
- Category
- process_creation
- Author
- frack113, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
- Published
- 2022-12-29
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation where ssh.exe is executed with settings indicative of SSH command proxying, including ProxyCommand= and PermitLocalCommand=yes combined with LocalCommand. Attackers can use these features to execute or relay commands through ssh.exe in a way that blends into normal remote access tooling. The detection relies on process creation telemetry including the parent Image (OpenSSH sshd.exe) and detailed Image/command-line contents for ssh.exe, plus specific known binary characteristics via imphash matching.
Reporting behind it
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/Binaries/Ssh/
- github.comhttps://github.com/LOLBAS-Project/LOLBAS/pull/211/files
- gtfobins.github.iohttps://gtfobins.github.io/gtfobins/ssh/
- man.openbsd.orghttps://man.openbsd.org/ssh_config#ProxyCommand
- man.openbsd.orghttps://man.openbsd.org/ssh_config#LocalCommand
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_ssh_proxy_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: ssh.exe Used as Proxy/Local Command Launcher via ProxyCommand and LocalCommand"
id: 5212abdb-7a2d-4a11-9bee-75c53058a6f7
status: test
description: This rule flags Windows process creation where ssh.exe is executed with settings indicative of SSH command proxying, including ProxyCommand= and PermitLocalCommand=yes combined with LocalCommand. Attackers can use these features to execute or relay commands through ssh.exe in a way that blends into normal remote access tooling. The detection relies on process creation telemetry including the parent Image (OpenSSH sshd.exe) and detailed Image/command-line contents for ssh.exe, plus specific known binary characteristics via imphash matching.
references:
- https://lolbas-project.github.io/lolbas/Binaries/Ssh/
- https://github.com/LOLBAS-Project/LOLBAS/pull/211/files
- https://gtfobins.github.io/gtfobins/ssh/
- https://man.openbsd.org/ssh_config#ProxyCommand
- https://man.openbsd.org/ssh_config#LocalCommand
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_ssh_proxy_execution.yml
author: frack113, Nasreddine Bencherchali, Huntrule Team
date: 2022-12-29
modified: 2025-10-16
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage: C:\Windows\System32\OpenSSH\sshd.exe
selection_cli_img:
- Image|endswith: \ssh.exe
- Product: OpenSSH for Windows
- Hashes|contains:
- IMPHASH=55b4964d29aad5438b9e950052dbbbc0
- IMPHASH=334d66c33503ccbf647c15b47c27eef4
- IMPHASH=27b0da080ef92afb37983d30d839141e
- IMPHASH=977eb4c263d384e47daa0712d34713ab
- IMPHASH=3eaadce9ae43d5a918bb082065815c3b
- IMPHASH=980fe6cf0d996ab1eedf877222e722aa
- IMPHASH=5f959422308ac3d721010d66647e100e
- IMPHASH=a49aaa3d03d1cd9c8dc7fca60f7f480b
- IMPHASH=dd335f759b6d5d6a8382b71dd9d65791
selection_cli_flags:
- CommandLine|contains: ProxyCommand=
- CommandLine|contains|all:
- PermitLocalCommand=yes
- " LocalCommand"
condition: selection_parent or all of selection_cli_*
falsepositives:
- Legitimate usage for administration purposes
level: medium
license: DRL-1.1
related:
- id: 7d6d30b8-5b91-4b90-a891-46cccaf29598
type: derived