
Category breakdown
Report covers the raw detections that opened the case: a port scan, a hit against the Emerging Threats “known compromised or hostile host” list, and Resource Development, MITRE’s term for infrastructure setup preceding the main activity. Brute Force groups four related detections: brute force on the SSH service, service brute force generally, and password guessing as its own attack pattern. Service lists the ET COMPROMISED hits again, tied specifically to SSH as the targeted remote service. Tactic summarizes the case: ten distinct MITRE ATT&CK tactics — Reconnaissance, Resource Development, Initial Access, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Command and Control, and Impact.Scope of the activity
MITRE ATT&CK defines fourteen tactics spanning an intrusion from initial reconnaissance to impact on the target. An actor touching ten of them against a single organization indicates a sustained campaign that progressed past an initial SSH brute-force attempt rather than a single scan that happened to be logged. The “ET COMPROMISED” tag originates from the Emerging Threats open ruleset, independent of OneFirewall’s own scoring — the host was already flagged by a separate detection engine before this correlation was built.Effect on response
Treating each of these detections as a separate SSH alert results in addressing symptoms individually. Viewing them as one actor’s progression through Credential Access into Lateral Movement and Command and Control changes the response to address the intrusion as a whole, rather than the login attempts that happened to trip a threshold first.Proof of Value engagements map incidents like this one across the full kill chain rather than as isolated alerts. Start a Proof of Value.

