{"id":"1f978c6a-4415-47fb-aca5-736a44d7ca3d","title":"Cisco Crypto Commands","description":"Show when private keys are being exported from the device, or when new certificates are installed","author":"Austin Clark","status":"test","level":"high","date":"2019-08-12","modified":"2023-01-04","tags":["attack.credential-access","attack.defense-impairment","attack.t1553.004","attack.t1552.004"],"technique_ids":["T1552.004","T1553.004"],"logsource":{"product":"cisco","service":"aaa"},"falsepositives":["Not commonly run by administrators. Also whitelist your known good certificates"],"references":["https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html"],"source_path":"rules/network/cisco/aaa/cisco_cli_crypto_actions.yml","source_sha256":"0876b77bfa952036a21803d35b378e3bf9f52417d1716dd67975a4f80c58bcf1","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/network/cisco/aaa/cisco_cli_crypto_actions.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Cisco Crypto Commands\nid: 1f978c6a-4415-47fb-aca5-736a44d7ca3d\nstatus: test\ndescription: Show when private keys are being exported from the device, or when new certificates are installed\nreferences:\n    - https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html\nauthor: Austin Clark\ndate: 2019-08-12\nmodified: 2023-01-04\ntags:\n    - attack.credential-access\n    - attack.defense-impairment\n    - attack.t1553.004\n    - attack.t1552.004\nlogsource:\n    product: cisco\n    service: aaa\ndetection:\n    keywords:\n        - 'crypto pki export'\n        - 'crypto pki import'\n        - 'crypto pki trustpoint'\n    condition: keywords\nfalsepositives:\n    - Not commonly run by administrators. Also whitelist your known good certificates\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1552.004","id":"T1552.004","name":"Private Keys","page":"techniques/enterprise/T1552.004/"},{"key":"enterprise/T1553.004","id":"T1553.004","name":"Install Root Certificate","page":"techniques/enterprise/T1553.004/"}],"data_path":"data/detection-rules/1f978c6a-4415-47fb-aca5-736a44d7ca3d.json","kind":"sigma"}
