Cross-source coverage
T1556.004 / ATT&CK
Modify Authentication Process: Network Device Authentication
2 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
Modify System Image may include implanted code to the operating system for network devices to provide access for adversaries using a specific password. The modification includes a specific password which is implanted in the operating system image via the patch. Upon authentication attempts, the inserted code will first check to see if the user input is the password. If so, access is granted. Otherwise, the implanted code will pass the credentials on for verification of potentially valid credentials.
- Tactics
- Defense Impairment · Persistence · Credential Access
- Platforms
- Network Devices
- Telemetry
-
networkconfignetwork:auth
How MITRE says to detect it DET0272
Detect Modification of Network Device Authentication via Patched System Images
Network Devices Analytic 0758
Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.
networkconfigunexpected OS image file upload or modification eventsnetwork:authrepeated successful authentications with previously unknown accounts or anomalous password acceptance
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| Cisco Dot1x Disabled | Medium | Sigma |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - AAA Policy Tampering | Undefined | SPL |