SSH Authorized Keys & sshd_config Modification for Persistence (T1098.004)
Detects unauthorized modifications to SSH 'authorized_keys' files or the '/etc/ssh/sshd_config' configuration file on Linux systems. These actions can be used for persistent access (key injection) or to weaken SSH security controls (e.g., enabling root login) and are typical indicators of account manipulation or compromise.
SentinelOne

