# False positive on SIEM rule SSH to the Internet

**URL:** <https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070>\
**Category:** SIEM\
**Created:** [May 18, 2020, 9:35am UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070 "2020-05-18T09:35:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 18, 2020, 9:35am UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070/1 "2020-05-18T09:35:57Z")

</div>

Hello,

This is the query for the "SSH to the Internet" Rule:

```
network.transport: tcp and destination.port:22 and (
    network.direction: outbound or (
        source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and
        not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16)
    )
)

```

It matches on internal ssh traffic however, because of `network.direction: outbound`, which is found in the auditbeat socket dataset.

Seems similar to [https://github.com/elastic/kibana/issues/57447](https://github.com/elastic/kibana/issues/57447)

But this on a 7.7, so not fixed yet?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [May 18, 2020, 2:25pm UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070/2 "2020-05-18T14:25:01Z")

</div>

Hey there Willem! Thanks for reaching out. It looks like the rule you mentioned - "SSH (Secure Shell) to the Internet" was updated for 7.7 to address the undesired behavior you brought up.

The rule's query was updated in [#61903](https://github.com/elastic/kibana/pull/61903/files#diff-12d5f7be1d74971ac7589911a99c3ae8) to be the following:

> network.transport:tcp and destination.port:22 and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip:(10.0.0.0/8 or 127.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16 or "::1")

I was able to confirm this change on a 7.7 build. Does this rule still show the older query for you on your 7.7 build?

Best,  
Yara

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 18, 2020, 3:48pm UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070/3 "2020-05-18T15:48:07Z")

</div>

Aaah rly sorry, didn't notice this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c724124f2f0a19ea6740c3336cf29ea869428054.png)

So I have to update the rules manually after an update, ok.. Check...

Tx!

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [May 18, 2020, 5:10pm UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070/4 "2020-05-18T17:10:41Z")

</div>

Awesome! And yes, if updates are available for prepackaged rules, you will see the banner (in your screenshot) and they can be manually updated by a user with the necessary privileges.

You can also view the current version and change history of each prepackaged rule in the release notes linked in the screenshot you attached. This version's (7.7) prepackaged rules release notes can be found [here](https://www.elastic.co/guide/en/siem/guide/7.7/prebuilt-rules-changelog.html).

In the future, if you run into an issue with a prebuilt rule and a fix is not yet available, you can select to duplicate the rule. This will provide you your own copy of the rule which you can then edit. The downside here is that the duplicated rule is then self-managed, but this can at least provide a temporary workaround until a fix is in.

Thanks again for reaching out and hope this helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2020, 5:10pm UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070/5 "2020-06-15T17:10:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
