Cross-source coverage

T1556.004 / ATT&CK

Modify Authentication Process: Network Device Authentication

2 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.

Modify System Image may include implanted code to the operating system for network devices to provide access for adversaries using a specific password. The modification includes a specific password which is implanted in the operating system image via the patch. Upon authentication attempts, the inserted code will first check to see if the user input is the password. If so, access is granted. Otherwise, the implanted code will pass the credentials on for verification of potentially valid credentials.

Platforms
Network Devices
Telemetry
networkconfignetwork:auth

How MITRE says to detect it DET0272

Detect Modification of Network Device Authentication via Patched System Images

Network Devices Analytic 0758

Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.

  • networkconfig unexpected OS image file upload or modification events
  • network:auth repeated successful authentications with previously unknown accounts or anomalous password acceptance

SigmaHQ/sigma

1 rule
Detection Severity Format
Cisco Dot1x Disabled Medium Sigma

splunk/security_content

1 rule
Detection Severity Format
Cisco ASA - AAA Policy Tampering Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.