{"id":"b094d9fb-b1ad-4650-9f1a-fb7be9f1d34b","title":"Cisco Show Commands Input","description":"See what commands are being input into the device by other people, full credentials can be in the history","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-11","modified":"2023-01-04","tags":["attack.credential-access","attack.t1552.003"],"technique_ids":["T1552.003"],"logsource":{"product":"cisco","service":"aaa"},"falsepositives":["Not commonly run by administrators, especially if remote logging is configured"],"references":[],"source_path":"rules/network/cisco/aaa/cisco_cli_input_capture.yml","source_sha256":"9a6202807e8fd0c8aa3582052fa5a3272952a5a7dd38ea9b1812b60b2786466c","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/network/cisco/aaa/cisco_cli_input_capture.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Cisco Show Commands Input\nid: b094d9fb-b1ad-4650-9f1a-fb7be9f1d34b\nstatus: test\ndescription: See what commands are being input into the device by other people, full credentials can be in the history\nauthor: Austin Clark\ndate: 2019-08-11\nmodified: 2023-01-04\ntags:\n    - attack.credential-access\n    - attack.t1552.003\nlogsource:\n    product: cisco\n    service: aaa\ndetection:\n    keywords:\n        - 'show history'\n        - 'show history all'\n        - 'show logging'\n    condition: keywords\nfalsepositives:\n    - Not commonly run by administrators, especially if remote logging is configured\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1552.003","id":"T1552.003","name":"Shell History","page":"techniques/enterprise/T1552.003/"}],"data_path":"data/detection-rules/b094d9fb-b1ad-4650-9f1a-fb7be9f1d34b.json","kind":"sigma"}
