Compliance Node Overview
MITRE ATT&CK T1563.001 (SSH Hijacking) is an Enterprise Lateral Movement sub-technique of T1563 (Remote Service Session Hijacking). Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote access on Linux and macOS systems. It allows a user to connect to another system via an encrypted tunnel, commonly authenticating through a password, certificate or the use of an asymmetric encryption key pair. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program, M1027 Password Policies, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-12, AC-17, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1563/001/
SHA-256 integrity: 0b9c2fc4b3b7840352b039f9e02f49b66591aa3562a687b2c40bf9e333196238
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1563.001: SSH Hijacking (https://attack.mitre.org/techniques/T1563/001/)
- MITRE ATT&CK Tactic TA0008: Lateral Movement (https://attack.mitre.org/tactics/TA0008/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access