Platform / product
cisco Sigma detection rules
17 community-maintained Sigma detection rules in the library target the cisco platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Cisco Clear Logs
highClear command history in network OS which is used for defense evasion
cisco · aaa
Cisco Crypto Commands
highShow when private keys are being exported from the device, or when new certificates are installed
cisco · aaa
Cisco Disabling Logging
highTurn off logging locally or remote
cisco · aaa
Cisco Local Accounts
highFind local accounts being created or modified as well as remote authentication configurations
cisco · aaa
Exploitation Indicators Of CVE-2023-20198
highDetecting exploitation indicators of CVE-2023-20198 a privilege escalation vulnerability in Cisco IOS XE Software Web UI.
cisco · syslog
Cisco Denial of Service
mediumDetect a system being shutdown or put into different boot mode
cisco · aaa
Cisco Dot1x Disabled
mediumDetects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.
cisco · aaa
Cisco Duo Successful MFA Authentication Via Bypass Code
mediumDetects when a successful MFA authentication occurs due to the use of a bypass code. A bypass code is a temporary passcode created by an administrator for a specific user to access a Duo-protected application. These are generally used as "backup codes," so that enrolled users who are having problems with their mobile devices (e.g., mobile service is disrupted, the device is lost or stolen, etc.) or who temporarily can't use their enrolled devices (on a plane without mobile data services) can still access their Duo-protected systems.
cisco · duo
Cisco File Deletion
mediumSee what files are being deleted from flash file systems
cisco · aaa
Cisco Modify Configuration
mediumModifications to a config that will serve an adversary's impacts or persistence
cisco · aaa
Cisco Show Commands Input
mediumSee what commands are being input into the device by other people, full credentials can be in the history
cisco · aaa
Cisco Sniffing
mediumShow when a monitor or a span/rspan is setup or modified
cisco · aaa
Cisco BGP Authentication Failures
lowDetects BGP failures which may be indicative of brute force attacks to manipulate routing
cisco · bgp
Cisco Collect Data
lowCollect pertinent data from the configuration files
cisco · aaa
Cisco Discovery
lowFind information about network devices that is not stored in config files
cisco · aaa
Cisco LDP Authentication Failures
lowDetects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
cisco · ldp
Cisco Stage Data
lowVarious protocols maybe used to put data on the device for exfil or infil
cisco · aaa