SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior.
SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns.
SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas.
Lateral Movement (1)