1200kmSECURITY RESEARCH

1200KM / sigma-rule

Cisco Local Accounts — Sigma Rule

Sigma rule 6d844f0f-1c18-41af-8f19-33e7654edfc3. Cisco Local Accounts — Sigma Rule. Find local accounts being created or modified as well as remote authentication configurations

Rule metadata and linked tags

Author: Austin Clark. Source status: test; severity: high. Source dates: 2019-08-12 / 2023-01-04.

{
  "product": "cisco",
  "service": "aaa"
}

Pinned original Sigma rule · Detection Rule License 1.1

Source SHA-256: 8dc681bb2d349b6803b32bdd3e24c4bdd37998da40dec46ca29887540b80f587

Detection logic

Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.

title: Cisco Local Accounts
id: 6d844f0f-1c18-41af-8f19-33e7654edfc3
status: test
description: Find local accounts being created or modified as well as remote authentication configurations
author: Austin Clark
date: 2019-08-12
modified: 2023-01-04
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.t1136.001
    - attack.t1098
logsource:
    product: cisco
    service: aaa
detection:
    keywords:
        - 'username'
        - 'aaa'
    condition: keywords
falsepositives:
    - When remote authentication is in place, this should not change often
level: high

Original YAML and metadata in JSON

False positives

  • When remote authentication is in place, this should not change often

Source references

No reviewed association in this snapshot.

Connected ecosystem references

Exact source-tagged techniques

Telemetry review

Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.