{"id":"T1098.004","name":"SSH Authorized Keys","url":"https://attack.mitre.org/techniques/T1098/004","tactics":["persistence","privilege-escalation"],"platforms":["ESXi","IaaS","Linux","macOS","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0126","stix_id":"x-mitre-detection-strategy--cf33849d-67f4-418e-9a41-6a6c082e576a","name":"Detection Strategy for SSH Key Injection in Authorized Keys","url":"https://attack.mitre.org/detectionstrategies/DET0126","analytics":[{"id":"AN0350","stix_id":"x-mitre-analytic--72dd4fd9-b6cb-4704-b845-0632fe224995","name":"Analytic 0350","description":"Adversary attempts to gain persistence by modifying ~/.ssh/authorized_keys via shell, text editor, echo or redirected output.","url":"https://attack.mitre.org/detectionstrategies/DET0126#AN0350","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write | PATH=/home/*/.ssh/authorized_keys","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TimeWindow","description":"Temporal window to correlate file writes and suspicious process launches (e.g., <60s)"},{"field":"UserContext","description":"Expected user-to-process correlation (e.g., root writing to non-root authorized_keys)"},{"field":"TargetPath","description":"Custom SSH path or user home variation (e.g., /etc/skel/.ssh/)"}],"live":true,"detection_strategies":["DET0126"],"techniques":["T1098.004"]},{"id":"AN0351","stix_id":"x-mitre-analytic--29988e3f-2f65-4fe5-9bf7-dae0cb869fc6","name":"Analytic 0351","description":"Insertion of public keys into authorized_keys using bash/zsh or editor tools, correlated with suspicious process ancestry.","url":"https://attack.mitre.org/detectionstrategies/DET0126#AN0351","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process: exec + filewrite: ~/.ssh/authorized_keys","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:auth","channel":"~/.ssh/authorized_keys","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-auth"}],"mutable_elements":[{"field":"ParentProcess","description":"Track unusual parent process writing to SSH config (e.g., curl -> bash)"},{"field":"InteractiveSessionFlag","description":"Flag whether shell session was interactive (normal) or spawned remotely (potential abuse)"}],"live":true,"detection_strategies":["DET0126"],"techniques":["T1098.004"]},{"id":"AN0352","stix_id":"x-mitre-analytic--d613771b-087c-43c4-8430-2a0bf6ebb314","name":"Analytic 0352","description":"Abuse of cloud metadata APIs or CLI to push SSH public keys to authorized_keys of virtual machines.","url":"https://attack.mitre.org/detectionstrategies/DET0126#AN0352","platforms":["IaaS"],"log_source_references":[{"name":"gcp:audit","channel":"compute.instances.setMetadata","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"gcp-audit"}],"mutable_elements":[{"field":"MetadataFieldName","description":"Custom metadata field (e.g., ssh-keys or custom-key)"},{"field":"AccountType","description":"Was it an admin, service principal, or automation user initiating?"},{"field":"TargetRoleEscalation","description":"Privilege level of the VM account receiving the key"}],"live":true,"detection_strategies":["DET0126"],"techniques":["T1098.004"]},{"id":"AN0353","stix_id":"x-mitre-analytic--e5b0d0ab-a464-4e9f-a1c0-dfb08a6ef53f","name":"Analytic 0353","description":"Direct modification of /etc/ssh/keys-<user>/authorized_keys or enabling SSH in sshd_config to support public key auth.","url":"https://attack.mitre.org/detectionstrategies/DET0126#AN0353","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"file write or edit","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"SSHConfigPath","description":"Could be modified SSH path in hypervisor"},{"field":"ESXiShellActivity","description":"Whether shell was enabled beforehand via DCUI or API"}],"live":true,"detection_strategies":["DET0126"],"techniques":["T1098.004"]},{"id":"AN0354","stix_id":"x-mitre-analytic--4d8e89c0-fbde-43fc-adc4-d2f50bec3193","name":"Analytic 0354","description":"Use of command-line like `ip ssh pubkey-chain` to bind SSH keys to privileged accounts on routers or switches.","url":"https://attack.mitre.org/detectionstrategies/DET0126#AN0354","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"ip ssh pubkey-chain","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"CLIUserRole","description":"Was the role allowed to push persistent config changes?"},{"field":"DeviceModel","description":"Variations in syntax or log behavior across device OS"}],"live":true,"detection_strategies":["DET0126"],"techniques":["T1098.004"]}],"live":true,"version":"1.0","techniques":["T1098.004"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2022-40684","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}