1200KM / sigma-rule
Cisco Local Accounts — Sigma Rule
Sigma rule 6d844f0f-1c18-41af-8f19-33e7654edfc3. Cisco Local Accounts — Sigma Rule. Find local accounts being created or modified as well as remote authentication configurations
Rule metadata and linked tags
Author: Austin Clark. Source status: test; severity: high. Source dates: 2019-08-12 / 2023-01-04.
{
"product": "cisco",
"service": "aaa"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 8dc681bb2d349b6803b32bdd3e24c4bdd37998da40dec46ca29887540b80f587
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Cisco Local Accounts
id: 6d844f0f-1c18-41af-8f19-33e7654edfc3
status: test
description: Find local accounts being created or modified as well as remote authentication configurations
author: Austin Clark
date: 2019-08-12
modified: 2023-01-04
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1136.001
- attack.t1098
logsource:
product: cisco
service: aaa
detection:
keywords:
- 'username'
- 'aaa'
condition: keywords
falsepositives:
- When remote authentication is in place, this should not change often
level: high
False positives
- When remote authentication is in place, this should not change often
Source references
No reviewed association in this snapshot.
Connected ecosystem references
Exact source-tagged techniques
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.