Modify Authentication Process: Network Device Authentication T1556.004

Tactics: Defense Impairment, Persistence, Credential Access

Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
command1in 1aaa authentication*, aaa authorization*, aaa local authentication*
message_id1in 1111008, 111010
sourcetype1eq 1cisco:asa

Top indicator values (8 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
commandin
aaa authentication*
1
commandin
aaa authorization*
1
commandin
aaa local authentication*
1
commandin
aaa-server*
1
commandin
no aaa*
1
message_idin
111008
17
message_idin
111010
17
sourcetypeeq
cisco:asa
113

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Network

Domain: Network

Sigma 1 rule

Splunk 1 rule