1200KM / sigma-rule
Cisco Crypto Commands — Sigma Rule
Sigma rule 1f978c6a-4415-47fb-aca5-736a44d7ca3d. Cisco Crypto Commands — Sigma Rule. Show when private keys are being exported from the device, or when new certificates are installed
Rule metadata and linked tags
Author: Austin Clark. Source status: test; severity: high. Source dates: 2019-08-12 / 2023-01-04.
{
"product": "cisco",
"service": "aaa"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 0876b77bfa952036a21803d35b378e3bf9f52417d1716dd67975a4f80c58bcf1
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Cisco Crypto Commands
id: 1f978c6a-4415-47fb-aca5-736a44d7ca3d
status: test
description: Show when private keys are being exported from the device, or when new certificates are installed
references:
- https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html
author: Austin Clark
date: 2019-08-12
modified: 2023-01-04
tags:
- attack.credential-access
- attack.defense-impairment
- attack.t1553.004
- attack.t1552.004
logsource:
product: cisco
service: aaa
detection:
keywords:
- 'crypto pki export'
- 'crypto pki import'
- 'crypto pki trustpoint'
condition: keywords
falsepositives:
- Not commonly run by administrators. Also whitelist your known good certificates
level: high
False positives
- Not commonly run by administrators. Also whitelist your known good certificates
Source references
Connected ecosystem references
Exact source-tagged techniques
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.