Cisco Network Security
Search Cisco Network Security rules.
Telemetry Evidence
These values show how indexed rules identify Cisco Network Security telemetry.Elastic
logs-cisco_ftd.* cisco_ftd Kusto
Cisco_Umbrella CiscoSDWANNetflow CiscoSEGEvent CiscoSyslogUTD CiscoWSAEvent CommonSecurityLog DeviceEventClassID = 733100 DeviceEventClassID in (733101, 733102, 733103, 733104, 733105) CiscoASA Panther
CiscoUmbrella.DNS ciscoumbrella Splunk
Cisco ASA Logs Cisco IOS Logs Cisco SD-WAN Auth Log Cisco SD-WAN NTCE 1000001 Cisco SD-WAN Service Proxy Access Logs Cisco Secure Firewall Threat Defense Connection Event Cisco Secure Firewall Threat Defense File Event Cisco Secure Firewall Threat Defense Intrusion Event
Detection Rules
Elastic #
- React2Shell Network Security Alert source high: This rule identifies network security alerts related to CVE-2025-55182 exploitation attempts from different network security integrations. CVE-2025-55182 is a critical remote code execution vulnerability in React Server Components (RSC) Flight protocol. The vulnerability allows attackers to execute arbitrary code on the server by sending specially crafted deserialization payloads that exploit prototype chain traversal to access the Function constructor.
T1059,T1059.007,T1190
Kusto #
- Cisco Cloud Security - Connection to non-corporate private network source medium: 'IP addresses of broadband links that usually indicates users attempting to access their home network, for example for a remote session to a home computer.'
T1041,T1573 - Cisco Cloud Security - Connection to Unpopular Website Detected source medium: 'Detects first connection to an unpopular website (possible malicious payload delivery).'
T1041,T1071,T1071.001 - Cisco Cloud Security - Crypto Miner User-Agent Detected source medium: 'Detects suspicious user agent strings used by crypto miners in proxy logs.'
T1041,T1071,T1071.001,T1496 - Cisco Cloud Security - Empty User Agent Detected source medium: 'Rule helps to detect empty and unusual user agent indicating web browsing activity by an unusual process other than a web browser.'
T1001,T1001.003 - Cisco Cloud Security - Hack Tool User-Agent Detected source medium: 'Detects suspicious user agent strings used by known hack tools'
T1020,T1021,T1046,T1059,T1102,T1557 - Cisco Cloud Security - Rare User Agent Detected source medium: 'Rule helps to detect a rare user-agents indicating web browsing activity by an unusual process other than a web browser.'
T1041,T1071,T1071.001 - Cisco Cloud Security - Request Allowed to harmful/malicious URI category source medium: 'It is reccomended that these Categories shoud be blocked by policies because they provide harmful/malicious content..'
T1041,T1071,T1071.001 - Cisco Cloud Security - Request to blocklisted file type source medium: 'Detects request to potentially harmful file types (.ps1, .bat, .vbs, etc.).'
T1105,T1189 - Cisco Cloud Security - URI contains IP address source medium: 'Malware can use IP address to communicate with C2.'
T1071,T1567 - Cisco Cloud Security - Windows PowerShell User-Agent Detected source medium: 'Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser.'
T1027,T1059,T1059.001,T1132
Show 36 more
- Cisco SDWAN - Intrusion Events source high: 'This Analytic rule will monitor Intrusion events in Cisco syslog data based on the provided Signature ID. This will create an incident if that Signature ID is found in the specified time range.'
T1189,T1190 - Cisco SDWAN - IPS Event Threshold source high: 'This analytic rule will monitor specific IPS event in the data.'
T1189,T1190 - Cisco SDWAN - Maleware Events source high: 'This analytic rule will monitor Malware Events in Syslog and Netflow Data'
T1587,T1587.001 - Cisco SDWAN - Monitor Critical IPs source high: 'This analytic rule will monitor critical IPs in Syslog and Netflow Data.'
T1071 - Cisco SEG - DLP policy violation source medium: 'Detects DLP policy violation.'
T1030 - Cisco SEG - Malicious attachment not blocked source high: 'Detects mails with malicious attachments which were not blocked.'
T1566 - Cisco SEG - Multiple large emails sent to external recipient source medium: 'Detects possible data exfiltration.'
T1030 - Cisco SEG - Multiple suspiciuos attachments received source high: 'Detects possibly phishing emails.'
T1566 - Cisco SEG - Possible outbreak source medium: 'Detects possible outbreak activity.'
T1566 - Cisco SEG - Potential phishing link source medium: 'Detects mails with suspicious links.'
T1566 - Cisco SEG - Suspicious link source high: 'Detects mails with suspicious links.'
T1566 - Cisco SEG - Suspicious sender domain source medium: 'Detects suspicious sender domain age.'
T1566 - Cisco SEG - Unexpected attachment source high: 'Detects possibly malicious attachments.'
T1566 - Cisco SEG - Unexpected link source medium: 'Detects mails with suspicious links.'
T1566 - Cisco SEG - Unscannable attacment source medium: 'Detects unscannable attachments in mails.'
T1566 - Cisco Umbrella - Connection to non-corporate private network source medium: 'IP addresses of broadband links that usually indicates users attempting to access their home network, for example for a remote session to a home computer.'
- Cisco Umbrella - Connection to Unpopular Website Detected source medium: 'Detects first connection to an unpopular website (possible malicious payload delivery).'
- Cisco Umbrella - Crypto Miner User-Agent Detected source medium: 'Detects suspicious user agent strings used by crypto miners in proxy logs.'
- Cisco Umbrella - Empty User Agent Detected source medium: 'Rule helps to detect empty and unusual user agent indicating web browsing activity by an unusual process other than a web browser.'
- Cisco Umbrella - Hack Tool User-Agent Detected source medium: 'Detects suspicious user agent strings used by known hack tools'
- Cisco Umbrella - Rare User Agent Detected source medium: 'Rule helps to detect a rare user-agents indicating web browsing activity by an unusual process other than a web browser.'
- Cisco Umbrella - Request Allowed to harmful/malicious URI category source medium: 'It is reccomended that these Categories shoud be blocked by policies because they provide harmful/malicious content..'
- Cisco Umbrella - Request to blocklisted file type source medium: 'Detects request to potentially harmful file types (.ps1, .bat, .vbs, etc.).'
- Cisco Umbrella - URI contains IP address source medium: 'Malware can use IP address to communicate with C2.'
- Cisco Umbrella - Windows PowerShell User-Agent Detected source medium: 'Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser.'
- Cisco WSA - Access to unwanted site source high: 'Detects when users attempting to access sites from high risk category.'
T1566 - Cisco WSA - Internet access from public IP source medium: 'Detects internet access from public IP.'
T1189 - Cisco WSA - Multiple attempts to download unwanted file source medium: 'Detects when multiple attempts to download unwanted file occur.'
T1189 - Cisco WSA - Multiple errors to resource from risky category source medium: 'Detects multiple connection errors to resource from risky category.'
T1102,T1189 - Cisco WSA - Multiple errors to URL source medium: 'Detects multiple connection errors to URL.'
T1102 - Cisco WSA - Multiple infected files source high: 'Detects multiple infected files on same source.'
T1189 - Cisco WSA - Suspected protocol abuse source medium: 'Detects possible protocol abuse.'
T1048 - Cisco WSA - Unexpected file type source medium: 'Detects unexpected file type.'
T1189 - Cisco WSA - Unexpected uploads source high: 'Detects unexpected file uploads.'
T1567 - Cisco WSA - Unexpected URL source medium: 'Detects unexpected URL.'
T1102 - Cisco WSA - Unscannable file or scan error source medium: 'Detects unscanned downloaded file.'
T1189
Panther #
- Cisco Umbrella Domain Blocked source low: Monitor blocked domains
- Cisco Umbrella Domain Name Fuzzy Matching source medium: Identify lookups to suspicious domains that could indicate a phishing attack.
- Cisco Umbrella Suspicious Domains source low: Monitor suspicious or known malicious domains
- DNS Base64 Encoded Query source medium: Detects DNS queries with Base64 encoded subdomains, which could indicate an attempt to obfuscate data exfil.
- Malicious SSO DNS Lookup source medium: The rule looks for DNS requests to sites potentially posing as SSO domains.
T1566
Splunk #
- Cisco ASA - AAA Policy Tampering source low: This analytic detects modifications to authentication and authorization (AAA) security policies on Cisco ASA devices via CLI or ASDM. AAA policies control critical security mechanisms including authentication attempts, lockout thresholds, password policies, and access control settings that protect administrative access to network infrastructure. Adversaries or malicious insiders may weaken authentication policies to facilitate brute force attacks, disable account lockouts to enable unlimited password attempts, reduce password complexity requirements, or modify authorization settings to elevate privileges and maintain persistent access. The detection monitors for command execution events containing AAA-related commands such as
aaa authentication,aaa authorization, oraaa local authentication, focusing on changes to authentication attempts, lockout policies, and access control configurations. Investigate any unauthorized modifications to AAA policies, especially changes that weaken security posture (increasing max-fail attempts, disabling lockouts, reducing password requirements), and verify these changes against approved change management processes and security policies.T1556,T1556.004 - Cisco ASA - Core Syslog Message Volume Drop source: Adversaries may intentionally suppress or reduce the volume of core Cisco ASA syslog messages to evade detection or cover their tracks. This hunting search is recommended to proactively identify suspicious downward shifts or absences in key syslog message IDs, which may indicate tampering or malicious activity. Visualizing this data in Splunk dashboards enables security teams to quickly spot anomalies and investigate potential compromise.
T1685 - Cisco ASA - Device File Copy Activity source low: This analytic detects file copy activity on Cisco ASA devices via CLI or ASDM. Adversaries may copy device files including configurations, logs, packet captures, or system files for reconnaissance, credential extraction, or data exfiltration. While legitimate file operations occur during backups and maintenance, unauthorized copies may indicate malicious activity. The detection monitors for command execution events (message ID 111008 or 111010) containing copy commands targeting running-config, startup-config, packet capture files, or other system files from disk0:, flash:, system:, or capture: locations. Investigate unexpected file copies, especially from non-administrative accounts, during unusual hours, or when combined with other suspicious activities.
T1005,T1530 - Cisco ASA - Device File Copy to Remote Location source low: This analytic detects file copy operations to remote locations on Cisco ASA devices via CLI or ASDM. Adversaries may exfiltrate device files including configurations, logs, packet captures, or system data to remote servers using protocols like TFTP, FTP, HTTP, HTTPS, SMB, or SCP. While legitimate backups to centralized servers are common, copies to unexpected destinations may indicate data exfiltration to attacker-controlled infrastructure. The detection monitors for command execution events (message ID 111008 or 111010) containing copy commands with remote protocol indicators (tftp:, ftp:, http:, https:, smb:, scp:). Investigate copies to unexpected destinations, from non-administrative accounts, or outside approved maintenance windows. We recommend adapting the detection filters to exclude known legitimate backup activities.
T1005,T1041,T1048,T1048.003 - Cisco ASA - Logging Disabled via CLI source medium: This analytic detects the disabling of logging functionality on a Cisco ASA device through CLI commands. Adversaries or malicious insiders may attempt to disable logging to evade detection and hide malicious activity. The detection looks for specific ASA syslog message IDs (111010, 111008) associated with command execution, combined with suspicious commands such as
no logging,logging disable,clear logging, orno logging host. Disabling logging on a firewall or security device is a strong indicator of defense evasion.T1685 - Cisco ASA - Logging Filters Configuration Tampering source low: This analytic detects tampering with logging filter configurations on Cisco ASA devices via CLI or ASDM. Adversaries may reduce logging levels or disable specific log categories to evade detection, hide their activities, or prevent security monitoring systems from capturing evidence of their actions. By lowering logging verbosity, attackers can operate with reduced visibility to security teams. The detection monitors for logging configuration commands (message ID 111008 or 111010) that modify logging destinations (asdm, console, history, mail, monitor, trap) without setting them to higher severity levels (5-notifications, 6-informational, 7-debugging), which may indicate an attempt to reduce logging verbosity. Investigate unauthorized logging configuration changes that reduce verbosity, especially changes performed by non-administrative accounts, during unusual hours, or without corresponding change management approval.
T1685 - Cisco ASA - Logging Message Suppression source low: This analytic detects suppression of specific logging messages on Cisco ASA devices using the "no logging message" command. Adversaries may suppress specific log message IDs to selectively disable logging of security-critical events such as authentication failures, configuration changes, or suspicious network activity. This targeted approach allows attackers to evade detection while maintaining normal logging operations that might otherwise alert administrators to complete logging disablement. The detection monitors for command execution events (message ID 111008 or 111010) containing the "no logging message" command, which is used to suppress specific message IDs from being logged regardless of the configured severity level. Investigate unauthorized message suppression, especially suppression of security-critical message IDs (authentication, authorization, configuration changes), suppression performed by non-administrative accounts, during unusual hours, or without documented justification.
T1070,T1685,T1685.001 - Cisco ASA - New Local User Account Created source low: This analytic detects creation of new user accounts on Cisco ASA devices via CLI or ASDM. Adversaries may create unauthorized user accounts to establish persistence, maintain backdoor access, or elevate privileges on network infrastructure devices. These rogue accounts can provide attackers with continued access even after initial compromise vectors are remediated. The detection monitors for ASA message ID 502101, which is generated whenever a new user account is created on the device, capturing details including the username, privilege level, and the administrator who created the account. Investigate unexpected account creations, especially those with elevated privileges (level 15), accounts created outside business hours, accounts with suspicious or generic names, or accounts created by non-administrative users.
T1078,T1078.003,T1136,T1136.001 - Cisco ASA - Packet Capture Activity source low: This analytic detects execution of packet capture commands on Cisco ASA devices via CLI or ASDM. Adversaries may abuse the built-in packet capture functionality to perform network sniffing, intercept credentials transmitted over the network, capture sensitive data in transit, or gather intelligence about network traffic patterns and internal communications. Packet captures can reveal usernames, passwords, session tokens, and confidential business data. The detection monitors for command execution events (message ID 111008 or 111010) containing "capture" commands, which are used to initiate packet capture sessions on specific interfaces or for specific traffic patterns on the ASA device. Investigate unauthorized packet capture activities, especially captures targeting sensitive interfaces (internal network segments, DMZ), captures configured to capture large volumes of traffic, captures with suspicious filter criteria, captures initiated by non-administrative accounts, or captures during unusual hours.
T1040,T1557 - Cisco ASA - Reconnaissance Command Activity source low: This analytic detects potential reconnaissance activities on Cisco ASA devices by identifying execution of multiple information-gathering "show" commands within a short timeframe. Adversaries who gain initial access to network infrastructure devices typically perform systematic reconnaissance to understand the device configuration, network topology, security policies, connected systems, and potential attack paths. This reconnaissance phase involves executing multiple "show" commands to enumerate device details, running configurations, active connections, routing information, and VPN sessions. The detection monitors for command execution events (message ID 111009) containing reconnaissance-oriented "show" commands (such as show running-config, show version, show interface, show crypto, show conn, etc.) and triggers when 7 or more distinct reconnaissance commands are executed within a 5-minute window by the same user. Investigate reconnaissance bursts from non-administrative accounts, unusual source IP addresses, activity during off-hours, methodical command sequences suggesting automated enumeration, or reconnaissance activity correlated with other suspicious behaviors. We recommend adapting the detection filters to exclude known legitimate administrative activities.
T1082,T1590,T1590.001,T1590.005
Show 69 more
- Cisco ASA - User Account Deleted From Local Database source low: This analytic detects deletion of user accounts from Cisco ASA devices via CLI or ASDM. Adversaries may delete local accounts to cover their tracks, remove evidence of their activities, disrupt incident response efforts, or deny legitimate administrator access during an attack. Account deletion can also indicate an attempt to hide the creation of temporary accounts used during compromise. The detection monitors for ASA message ID 502102, which is generated whenever a local user account is deleted from the device, capturing details including the deleted username, privilege level, and the administrator who performed the deletion. Investigate unexpected account deletions, especially those involving privileged accounts (level 15), deletions performed outside business hours, deletions by non-administrative users, or deletions that coincide with other suspicious activities.
T1070,T1070.008,T1531 - Cisco ASA - User Account Lockout Threshold Exceeded source low: This analytic detects user account lockouts on Cisco ASA devices resulting from excessive failed authentication attempts. Account lockouts may indicate brute force attacks, password spraying campaigns, credential stuffing attempts using compromised credentials from external breaches, or misconfigured automation attempting authentication with incorrect credentials. These activities represent attempts to gain unauthorized access to network infrastructure. The detection monitors for ASA message ID 113006, which is generated when a user account is locked out after exceeding the configured maximum number of failed authentication attempts, capturing the locked account name and the failure threshold that was exceeded. Investigate account lockouts for privileged or administrative accounts, multiple simultaneous lockouts affecting different accounts (suggesting password spraying), lockouts originating from unusual source IP addresses, lockouts during off-hours, or patterns suggesting automated attack tools.
T1110,T1110.001,T1110.003 - Cisco ASA - User Privilege Level Change source low: This analytic detects privilege level changes for user accounts on Cisco ASA devices via CLI or ASDM. Adversaries may escalate account privileges to gain elevated access to network infrastructure, enable additional command execution capabilities, or establish higher-level persistent access. Privilege levels on Cisco ASA range from 0 (lowest) to 15 (full administrative access), with level 15 providing complete device control. The detection monitors for ASA message ID 502103, which is generated whenever a user account's privilege level is modified, capturing both the old and new privilege levels along with the username and administrator who made the change. Investigate unexpected privilege changes, especially escalations to level 15, substantial privilege increases (e.g., from level 1 to 15), changes performed outside business hours, changes by non-administrative users, or changes without corresponding change management tickets.
T1078,T1078.003,T1098 - Cisco Configuration Archive Logging Analysis source: This analytic provides comprehensive monitoring of configuration changes on Cisco devices by analyzing archive logs. Configuration archive logging captures all changes made to a device's configuration, providing a detailed audit trail that can be used to identify suspicious or malicious activities. This detection is particularly valuable for identifying patterns of malicious configuration changes that might indicate an attacker's presence, such as the creation of backdoor accounts, SNMP community string modifications, and TFTP server configurations for data exfiltration. By analyzing these logs, security teams can gain a holistic view of configuration changes across sessions and users, helping to detect sophisticated attack campaigns like those conducted by threat actors such as Static Tundra.
T1098,T1505,T1505.003,T1685 - Cisco IOS Suspicious Privileged Account Creation source low: This analytic detects the creation of privileged user accounts on Cisco IOS devices, which could indicate an attacker establishing backdoor access. The detection focuses on identifying when user accounts are created with privilege level 15 (the highest administrative privilege level in Cisco IOS) or when existing accounts have their privileges elevated. This type of activity is particularly concerning when performed by unauthorized users or during unusual hours, as it may represent a key step in establishing persistence following the exploitation of vulnerabilities like CVE-2018-0171 in Cisco Smart Install. Threat actors like Static Tundra have been observed creating privileged accounts as part of their attack chain after gaining initial access to network devices.
T1078,T1136 - Cisco IOS XE Guestshell Activation and Destroy source low: This analytic detects Cisco IOS-XE guestshell enable activity followed by activation and destroy lifecycle logs. The detection focuses on HA_EM command logging for "guestshell enable" and "guestshell destroy", VMAN activation and destroy messages, and IM/IOX guestshell activation logs observed on some IOS-XE images.
T1059,T1611 - Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal source low: This analytic detects Cisco IOS-XE command sequences where show logging, clear logging, and exit occur within a short period. It also detects the pattern where a loopback interface is removed before clearing logs and exiting.
T1070,T1685,T1685.005 - Cisco IOS XE Reconnaissance Command Activity source low: This analytic detects bursts of Cisco IOS or NX-OS discovery commands associated with Salt Typhoon tradecraft. Adversaries who gain initial access to network infrastructure devices typically perform systematic reconnaissance to understand the device configuration, network topology, security policies, connected systems, and potential attack paths. This reconnaissance phase involves executing multiple "show" commands to enumerate device details, running configurations, active connections, routing information, and VPN sessions.
T1016,T1082,T1590 - Cisco IOS XE Remote Access Probe Burst source low: This analytic detects bursts of ping, SSH, and Telnet commands issued from Cisco IOS or NX-OS devices. The Salt Typhoon notes describe repeated SSH, Telnet-to-port-22, and ping activity across multiple IP addresses in a short time window.
T1018,T1021,T1021.004,T1046 - Cisco IOS XE Request Platform Package Describe Shell Pattern source medium: This analytic detects Cisco IOS-XE "request platform software package describe" commands containing suspicious shell-style filename patterns. Indicative of Slat Typhoon tradecraft.
T1059,T1190 - Cisco IOS XE Tunnel Interface Configuration source low: This analytic detects creation of a Cisco IOS-XE tunnel interface with tunnel source, tunnel destination, and an IP address in the 10.10.12.0 network. The Salt Typhoon notes identify this tunnel configuration pattern as suspicious.
T1090,T1572 - Cisco IOS XE VTY Access Class Tampering source low: This analytic detects rapid modification of Cisco IOS-XE VTY access-class settings. The Salt Typhoon notes describe configure HTTP activity followed by line vty changes and removal/re-application of an access-class within 60 seconds.
T1021,T1685 - Cisco IOS XE WebUI Login From IOSd Local Port source medium: This analytic detects Cisco IOS-XE WebUI authentication failure and success logs that include local port 21111. This is a strong an indicator of WebUI exploitation because normal users should not authenticate through the underlying IOS-XE Linux shell path.
T1078,T1190 - Cisco IOS XE WebUI Programmatic Configuration source low: This analytic detects Cisco IOS-XE configuration changes performed by the WebUI WSMA process.
T1078,T1190 - Cisco Network Interface Modifications source low: This analytic detects the creation or modification of network interfaces on Cisco devices, which could indicate an attacker establishing persistence or preparing for lateral movement. After gaining initial access to network devices, threat actors like Static Tundra often create new interfaces (particularly loopback interfaces) to establish covert communication channels or maintain persistence. This detection specifically looks for the configuration of new interfaces, interface state changes, and the assignment of IP addresses to interfaces. These activities are particularly concerning when they involve unusual interface names or descriptions containing suspicious terms.
T1021,T1133,T1556 - Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity source medium: This analytic detects a exploitation activity attempts of targeting Cisco Catalyst SD-WAN Manager. It leverages the "serviceproxy_access.log" and identifies source-host combinations that perform all key stages of the exploitation as reported in public POCs in a short period: authentication/config collection (
.dca), upload actions (uploadAck), and payload-style access (.gz/*). The behavior can indicate attempted exploitation activity associated with Cisco Catalyst SD-WAN Manager vulnerabilities CVE-2026-20122 (Arbitrary File Overwrite) and CVE-2026-20128 (Information Disclosure).T1190 - Cisco SD-WAN - Low Frequency Rogue Peer source low: This analytic identifies low-frequency Cisco SD-WAN control peering activity from control-connection-state-change events where "new-state:up". It extracts "peer-type" and "peer-system-ip", groups events by these two fields, and counts how often each combination appears within the selected time window. Combinations whose count is less than or equal to the defined threshold (currently <=3 occurrences in the search window) are flagged as rare. Analysts should prioritize peer identities that are rarely observed in the environment, particularly those involving unexpected peer-type roles or unfamiliar peer-system-ip values. Rare control-plane peers may indicate misconfiguration, unauthorized SD-WAN components, infrastructure drift, or potentially malicious control-plane connection attempts. Findings might indicate the potential exploitation of CVE-2026-20127. Note that the threshold setting is set to "3", but its highly recommended that this should be adapted to the environment before deploying this search.
T1190 - Cisco SD-WAN - Peering Activity source: This analytic detects Cisco SD-WAN
control-connection-state-changeevents where a control connection transitions. It extracts and highlights key triage fields includingpeer-type,peer-system-ip,public-ip, andpublic-port. Analysts should manually validate whether thepeer-system-ipmatches the expected SD-WAN addressing schema and device inventory, whether the event timing aligns with known operational activity (maintenance, failover, or planned changes), and whether thepublic-ipis an expected source for control peering in the environment. Treatpeer-type:vmanageevents with higher scrutiny, especially when peer or source IP values are previously unseen.T1190 - Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity source: This hunting search is designed to surface source IP activity using uncommon HTTP user-agents across multiple URI paths in Cisco SD-WAN Manager serviceproxy access logs. It looks for source and user-agent combinations that access more than one distinct URI, then keeps only low-volume behavior (
requests<=50) to reduce noise from normal high-volume traffic. Use this hunt to pivot onhttp_user_agentandsrcand identify possible automation, scripted reconnaissance, or exploitation attempts.T1595 - Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication source: This analytic identifies multiple unique source IP addresses successfully authenticating as
vmanage-adminvia SSH publickey on Cisco Catalyst SD-WAN control components within a short time window. This aligns with IoC guidance for CVE-2026-20127 (cisco-sa-sdwan-rpa-EHchtZk), which warns that compromised systems may showAccepted publickey for vmanage-adminentries from unauthorized IPs. Validate flagged source IPs against known System IPs in SD-WAN Manager and investigate unexpected or concurrent sources.T1595 - Cisco SD-WAN Multiple SSH key Authentication from Same Source source: This hunting analytic identifies multiple distinct SSH publickey fingerprints used to authenticate the same user from the same source IP against a Cisco Catalyst SD-WAN control component. After legitimate vManage key rotation or reboot, a new key may appear but the old key should no longer be used; continued use of more than one key from the same source may indicate unauthorized key injection or persistence related to CVE-2026-20127 (cisco-sa-sdwan-rpa-EHchtZk). Validate flagged keys and source IPs against known System IPs in SD-WAN Manager and investigate unexpected combinations.
T1595 - Cisco Secure Firewall - Binary File Type Download source low: The following analytic detects file downloads involving executable, archive, or scripting-related file types that are commonly used in malware delivery. These file types include formats like PE executables, shell scripts, autorun files, installers, and known testing samples such as EICAR. This detection leverages Cisco Secure Firewall Threat Defense logs and enriches the results using a filetype lookup to provide context. If confirmed malicious, these downloads could indicate the initial infection vector, malware staging, or scripting abuse.
T1059,T1203 - Cisco Secure Firewall - Bits Network Activity source low: The following analytic detects the use of the Background Intelligent Transfer Service (BITS) client application in allowed outbound connections. It leverages logs from Cisco Secure Firewall Threat Defense devices and identifies instances where BITS is used to initiate downloads from non-standard or unexpected domains. While BITS is a legitimate Windows service used for downloading updates, it is also commonly abused by adversaries to stealthily retrieve payloads or tools. This analytic filters out known Microsoft Edge update URLs and focuses on connections that may indicate suspicious or unauthorized file transfers. If confirmed malicious, this could represent a command and control (C2) channel or a download of malware or tooling as part of an attack chain.
- Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint source medium: The following analytic detects the use of known suspicious SSL certificates in any observed event where the SSL_CertFingerprint field is present. It leverages Cisco Secure Firewall logs and compares the SSL certificate SHA1 fingerprint against a blacklist of certificates associated with malware distribution, command and control (C2) infrastructure, or phishing campaigns. This activity is significant as adversaries often reuse or self-sign certificates across malicious infrastructure, allowing defenders to track and detect encrypted sessions even when domains or IPs change. If confirmed malicious, this may indicate beaconing, malware download, or data exfiltration over TLS/SSL.
T1071,T1071.001,T1573,T1573.002,T1587,T1587.002 - Cisco Secure Firewall - Blocked Connection source low: The following analytic detects a blocked connection event by identifying a "Block" value in the action field. It leverages logs from Cisco Secure Firewall Threat Defense devices. This activity is significant as it can identify attempts from users or applications initiating network connection to explicitly or implicitly blocked range or zones. If confirmed malicious, attackers could be attempting to perform a forbidden action on the network such as data exfiltration, lateral movement, or network disruption.
T1018,T1046,T1110,T1203,T1595,T1595.002 - Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt source medium: This analytic detects exploitation activity of CVE-2025-5777 using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signature 65118 (Citrix NetScaler memory overread attempt) is triggered If confirmed malicious, this behavior is highly indicative of a potential exploitation of CVE-2025-5777.
T1059,T1203 - Cisco Secure Firewall - Communication Over Suspicious Ports source low: The following analytic detects potential reverse shell activity by identifying connections involving ports commonly associated with remote access tools, shell listeners, or tunneling utilities. It leverages Cisco Secure Firewall Threat Defense logs and monitors destination ports against a list of non-standard, high-risk port values often used in post-exploitation scenarios. Adversaries frequently configure tools like netcat, Meterpreter, or other backdoors to listen or connect over uncommon ports such as 4444, 2222, or 51820 to bypass standard monitoring and firewall rules. If confirmed malicious, this activity may represent command and control (C2) tunneling, lateral movement, or unauthorized remote access.
T1021,T1055,T1059,T1059.001,T1105,T1219 - Cisco Secure Firewall - Connection to File Sharing Domain source low: The following analytic detects outbound connections to commonly abused file sharing and pastebin-style hosting domains. It leverages Cisco Secure Firewall Threat Defense logs and focuses on allowed connections (action=Allow) where the url field matches a list of known data hosting or temporary storage services. While many of these platforms serve legitimate purposes, they are frequently leveraged by adversaries for malware delivery, data exfiltration, command and control (C2) beacons, or staging of encoded payloads. This analytic is valuable for identifying potential abuse of legitimate infrastructure as part of an attacker's kill chain. If confirmed malicious, this activity may indicate tool staging, credential dumping, or outbound data leaks over HTTP(S).
T1071,T1071.001,T1090,T1090.002,T1105,T1567 - Cisco Secure Firewall - File Download Over Uncommon Port source low: The following analytic detects file transfers flagged as malware that occurred over non-standard ports (other than 80 and 443). Adversaries may attempt to bypass protocol-based detection or use alternate ports to blend in with other traffic. This analytic identifies these non-conventional flows and surfaces potential evasion techniques. If confirmed malicious this indicate potential malware delivery or other nefarious activity.
T1105,T1571 - Cisco Secure Firewall - High EVE Threat Confidence source low: The following analytic detects connections with a high Encrypted Visibility Engine (EVE) threat confidence score, indicating potentially malicious behavior within encrypted traffic. It leverages Cisco Secure Firewall Threat Defense logs and evaluates the EVE_ThreatConfidencePct field, which reflects the system's confidence in classifying encrypted sessions as threats based on machine learning models and behavioral analysis. A score equal to or greater than 80 suggests the connection is highly likely to be associated with malware command and control (C2), remote access tools, or suspicious tunneling behavior. If confirmed malicious, this may indicate covert communication over TLS from compromised hosts.
T1041,T1071,T1071.001,T1105,T1573,T1573.002 - Cisco Secure Firewall - High Priority Intrusion Classification source medium: This analytic identifies high-severity intrusion events based on the classification assigned to Snort rules within Cisco Secure Firewall logs. It leverages Cisco Secure Firewall Threat Defense logs and focuses on events classified as: - A Network Trojan was Detected - Successful Administrator Privilege Gain - Successful User Privilege Gain - Attempt to Login By a Default Username and Password - Known malware command and control traffic - Known malicious file or file based exploit - Known client side exploit attempt - Large Scale Information Leak" These classifications typically represent significant threats such as remote code execution, credential theft, lateral movement, or malware communication. Detection of these classifications should be prioritized for immediate investigation.
T1003,T1071,T1078,T1190,T1203 - Cisco Secure Firewall - High Volume of Intrusion Events Per Host source low: The following analytic detects internal systems that generate an unusually high volume of intrusion detections within a 30-minute window. It leverages Cisco Secure Firewall Threat Defense logs, specifically focusing on the IntrusionEvent event type, to identify hosts that trigger more than 15 Snort-based signatures during that time. A sudden spike in intrusion alerts originating from a single host may indicate suspicious or malicious activity such as malware execution, command-and-control communication, vulnerability scanning, or lateral movement. In some cases, this behavior may also be caused by misconfigured or outdated software repeatedly tripping detection rules. Systems exhibiting this pattern should be triaged promptly, as repeated Snort rule matches from a single source are often early indicators of compromise, persistence, or active exploitation attempts.
T1059,T1071,T1595,T1595.002 - Cisco Secure Firewall - Intrusion Events by Threat Activity source low: This analytic detects intrusion events from known threat activity using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where one or multiple Snort signatures associated with a known threat or threat actor activity have been triggered within a one-hour time window. The detection uses a lookup table (cisco_snort_ids_to_threat_mapping) to map Snort signature IDs to known threat actors and their techniques. When multiple signatures associated with the same threat actor are triggered within the time window, and the count of unique signatures matches or exceeds the expected number of signatures for that threat technique, an alert is generated. This helps identify potential coordinated threat activity in your network environment by correlating related intrusion events that occur in close temporal proximity. Currently, this detection will alert on the following threat actors or malware families as defined in the cisco_snort_ids_to_threat_mapping lookup: * AgentTesla * Amadey * ArcaneDoor * AsyncRAT * CastleRAT * Chafer * DCRAT * LokiBot * Lumma Stealer * Nobelium * Quasar * Remcos * Snake * Static Tundra * Xworm To add or update threat actors, update the cisco_snort_ids_to_threat_mapping.csv lookup file with new or modified threat names and associated Snort signature IDs.
T1041,T1573,T1573.002 - Cisco Secure Firewall - Lumma Stealer Activity source medium: This analytic detects Lumma Stealer activity using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where four of the following Snort signature IDs 64793, 64794, 64797, 64798, 64799, 64800, 64801, 62709, 64167, 64168, 64169, 64796, 62710, 62711, 62712, 62713, 62714, 62715, 62716, 62717, 64812, 64810, 64811 occurs in the span of 15 minutes from the same host. If confirmed malicious, this behavior is highly indicative of a successful infection of Lumma Stealer.
T1027,T1190,T1204,T1210 - Cisco Secure Firewall - Lumma Stealer Download Attempt source low: This analytic detects Lumma Stealer download attempts using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signatures with IDs 64797, 64798, 64799, 64800, 64801, 64167, 64168, 64169 have been triggered. If confirmed malicious, this behavior could indicate an active infection of Lumma Stealer.
T1041,T1573,T1573.002 - Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt source low: This analytic detects Lumma Stealer outbound connection attempts using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signatures with IDs 64797, 64798, 64799, 64800, 64801, 64167, 64168, 64169, 62709 have been triggered. If confirmed malicious, this behavior could indicate an active infection of Lumma Stealer.
T1041,T1573,T1573.002 - Cisco Secure Firewall - Malware File Downloaded source low: The following analytic detects file downloads that were classified as malware by Cisco Secure Firewall Threat Defense. It relies on the
SHA_Dispositionfield with a value of "Malware" and includes metadata such as file name, file_hash hash, and threat classification. This analytic is critical for surfacing file-based threats that are identified via Cisco's AMP or Threat Grid integrations. If confirmed malicious, this could indicate delivery of malware.T1105,T1203 - Cisco Secure Firewall - Oracle E-Business Suite Correlation source medium: This correlation rule identifies potential exploitation attempts of Oracle E-Business Suite vulnerabilities (CVE-2025-61882 and CVE-2025-61884) by correlating multiple intrusion signatures from Cisco Secure Firewall Threat Defense logs. The detection looks for specific signatures that indicate attempts to exploit the TemplatePreview functionality and vulnerable SyncServlet endpoints as well as post compromise activity involving Cl0p. By correlating these signatures, the analytic aims to identify coordinated exploitation attempts that may indicate an attacker is targeting Oracle E-Business Suite installations. Security teams should investigate any instances of these correlated signatures, especially if they are found in conjunction with other suspicious network activity or on systems that should not be exposed to such threats.
T1190 - Cisco Secure Firewall - Oracle E-Business Suite Exploitation source medium: This analytic detects vulnerability exploitation and post-compromise activity associated with Oracle E-Business Suite web-application vulnerabilities, CVE-2025-61882 and CVE-2025-61884. SIDs 65413-65415 detect detect Java.Backdoor.Cl0p variant payload downloads and Java.Backdoor.Cl0p outbound command-and-control connection attempts. SIDs 65456, 65377 and 65378 detect attempts to exploit these vulnerabilities. Security teams should investigate any instances of these signatures, especially if they are found in conjunction with other suspicious network activity or on systems that should not be exposed to such threats.
T1190 - Cisco Secure Firewall - Possibly Compromised Host source low: The following analytic highlights high-impact intrusion events assigned by Cisco Secure Firewall. This detection leverages Cisco Secure Firewall Threat Defense logs and specifically the IntrusionEvent event type and
Impactfield assigned by Cisco Secure Firewall looking for an impact score of 1 or 2. If confirmed malicious this may indicate a potential compromised host.T1059,T1203,T1587,T1587.001 - Cisco Secure Firewall - Potential Data Exfiltration source low: The following analytic detects potentially suspicious large volumes of data sent by the connection initiator on flows from internal to external networks. It leverages Cisco Secure Firewall Threat Defense ConnectionEvent logs and thresholds on InitiatorBytes (bytes transmitted by the initiator), which for typical inside-initiated client sessions approximates upload or outbound payload from the internal host and avoids flagging large downloads where most bytes appear in ResponderBytes. Connections where the initiator sent at least 100 MB are flagged, as these may indicate unauthorized data exfiltration, especially if associated with unusual users, hosts, or processes. This analytic is scoped to inside-to-outside flows using a macro (cisco_secure_firewall_inside_to_outside) to abstract environment-specific zone definitions. If confirmed malicious, this behavior may reflect data staging and exfiltration over an encrypted or stealthy transport.
T1041,T1048,T1048.003,T1567,T1567.002 - Cisco Secure Firewall - Privileged Command Execution via HTTP source low: This analytic detects HTTP requests to privileged execution paths on Cisco routers, specifically targeting the
/level/15/exec/-/*endpoint using Cisco Secure Firewall Intrusion Events. This detection leverages Snort signature 65370 to identify requests to these sensitive endpoints, which when combined with other indicators may signal active exploitation or post-compromise activity.T1059,T1505,T1505.003 - Cisco Secure Firewall - Rare Snort Rule Triggered source: This analytic identifies Snort signatures that have triggered only once in the past 7 days across all Cisco Secure Firewall IntrusionEvent logs. While these rules typically do not trigger in day-to-day network activity, their sudden appearance may indicate early-stage compromise, previously unseen malware, or reconnaissance activity against less commonly exposed services. Investigating these outliers can provide valuable insight into new or low-noise adversary behaviors.
T1583,T1583.006,T1598 - Cisco Secure Firewall - React Server Components RCE Attempt source medium: This analytic detects exploitation activity of CVE-2025-55182 using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signature 65554 (React Server Components remote code execution attempt) is triggered If confirmed malicious, this behavior could be indicative of a potential exploitation of CVE-2025-55182.
T1190 - Cisco Secure Firewall - Remote Access Software Usage Traffic source low: The following analytic detects network traffic associated with known remote access software applications that are covered by Cisco Secure Firewall Application Detectors, such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. It leverages Cisco Secure Firewall Threat Defense Connection Event. This activity is significant because adversaries often use remote access tools to maintain unauthorized access to compromised environments. If confirmed malicious, this activity could allow attackers to control systems remotely, exfiltrate data, or deploy additional malware, posing a severe threat to the organization's security.
T1219 - Cisco Secure Firewall - Repeated Blocked Connections source low: The following analytic detects repeated blocked connection attempts from the same initiator to the same responder within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies connections where the action is set to Block, and the number of occurrences reaches or exceeds a threshold of ten within a one-minute span. This pattern may indicate a misconfigured application, unauthorized access attempts, or early stages of a brute-force or scanning operation. If confirmed malicious, this behavior may represent an attacker probing the network, attempting lateral movement, or testing firewall rules for weaknesses.
T1018,T1046,T1110,T1203,T1595,T1595.002 - Cisco Secure Firewall - Repeated Malware Downloads source low: The following analytic detects repeated malware file downloads initiated by the same internal host (src) within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies
FileEventevents with aSHA_Dispositionof "Malware" andFileDirectionset to "Download". If ten or more such events occur from the same host within five minutes, this analytic will trigger. This activity may indicate the host is compromised and repeatedly retrieving malicious content either due to command-and-control, malware staging, or automation. If confirmed malicious, this behavior may represent an infection in progress, persistence mechanism, or a malicious downloader.T1027,T1105 - Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts source low: This analytic identifies Snort intrusion signatures that have been triggered by ten or more distinct internal IP addresses within a one-hour window. It leverages Cisco Secure Firewall Threat Defense logs and focuses on the IntrusionEvent event type to detect activity that may indicate broad targeting or mass exploitation attempts. This behavior is often associated with opportunistic scanning, worm propagation, or automated exploitation of known vulnerabilities across multiple systems. If confirmed malicious, this could represent the early phase of a coordinated attack aiming to gain a foothold on several hosts or move laterally across the environment.
T1027,T1105 - Cisco Secure Firewall - SSH Connection to Non-Standard Port source low: This analytic detects inbound SSH connections to non-standard ports on network devices using Cisco Secure Firewall Intrusion Events. APT actors have been observed enabling SSH servers on high, non-default TCP ports to maintain encrypted remote access to compromised network infrastructure. This detection leverages Snort signature 65369 to identify SSH protocol traffic on unusual ports, which may indicate persistence mechanisms or backdoor access established by threat actors.
T1021,T1021.004 - Cisco Secure Firewall - SSH Connection to sshd_operns source low: This analytic detects inbound SSH connections to the sshd_operns service on network devices using Cisco Secure Firewall Intrusion Events. APT actors have been observed enabling sshd_operns and opening it on non-standard ports to maintain encrypted remote access to compromised network infrastructure. This detection leverages Snort signature 65368 to identify connections to this service, which when combined with other indicators may signal persistent access mechanisms established by threat actors.
T1021,T1021.004 - Cisco Secure Firewall - Static Tundra Smart Install Abuse source medium: This analytic detects activity associated with "Static Tundra" threat actor abuse of the Cisco Smart Install (SMI) protocol using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify occurrences of Smart Install exploitation and protocol abuse, including denial-of-service and buffer overflow attempts. The detection triggers when multiple Cisco Smart Install-related Snort signatures are observed in a short period from the same source, which is indicative of active exploitation or reconnaissance against Cisco devices that expose SMI.
T1190,T1210,T1499 - Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity source medium: This analytic detects exploitation activity of CVE-2023-27532 using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signature 61514 (Veeam Backup and Replication credential dump attempt) is followed within a 5-minute window by 64795 (Veeam Backup and Replication xp_cmdshell invocation attempt), which detects the use of
xp_cmdshell, a common post-exploitation technique. If confirmed malicious, this behavior is highly indicative of a successful exploitation of CVE-2023-27532, followed by remote command execution or credential dumping.T1003,T1003.001,T1059,T1059.001,T1190,T1210 - Cisco Secure Firewall - Wget or Curl Download source low: The following analytic detects outbound connections initiated by command-line tools such as curl or wget. It leverages Cisco Secure Firewall Threat Defense logs and identifies allowed connections (action=Allow) where either the EVE_Process or ClientApplication fields indicate use of these utilities. While curl and wget are legitimate tools commonly used for software updates and scripting, adversaries often abuse them to download payloads, retrieve additional tools, or establish staging infrastructure from compromised systems. If confirmed malicious, this behavior may indicate the download phase of an attack chain or a command-and-control utility retrieval.
T1053,T1053.003,T1059,T1071,T1071.001,T1105 - Cisco SNMP Community String Configuration Changes source low: This analytic detects changes to SNMP community strings on Cisco devices, which could indicate an attacker establishing persistence or attempting to extract credentials. After gaining initial access to network devices, threat actors like Static Tundra often modify SNMP configurations to enable unauthorized monitoring and data collection. This detection specifically looks for the configuration of SNMP community strings with read-write (rw) or read-only (ro) permissions, as well as the configuration of SNMP hosts that may be used to exfiltrate data. These activities are particularly concerning as they may represent attempts to establish persistent access or extract sensitive information from compromised devices.
T1040,T1552,T1685 - Cisco TFTP Server Configuration for Data Exfiltration source medium: This analytic detects the configuration of TFTP services on Cisco IOS devices that could be used to exfiltrate sensitive configuration files. Threat actors like Static Tundra have been observed configuring TFTP servers to make device configuration files accessible for exfiltration after gaining initial access. The detection specifically looks for commands that expose critical configuration files such as startup-config, running-config, and other sensitive system information through TFTP. This activity is particularly concerning as it may represent an attempt to steal credentials, network topology information, and other sensitive data stored in device configurations.
T1005,T1567 - Detect ARP Poisoning source medium: The following analytic detects ARP Poisoning attacks by monitoring for Dynamic ARP Inspection (DAI) errors on Cisco network devices. It leverages logs from Cisco devices, specifically looking for events where the ARP inspection feature has disabled an interface due to suspicious activity. This activity is significant because ARP Poisoning can allow attackers to intercept, modify, or disrupt network traffic, leading to potential data breaches or denial of service. If confirmed malicious, this could enable attackers to perform man-in-the-middle attacks, compromising the integrity and confidentiality of network communications.
T1200,T1498,T1557,T1557.002 - Detect IPv6 Network Infrastructure Threats source medium: The following analytic detects IPv6 network infrastructure threats by identifying suspicious activities such as IP and MAC address theft or packet drops. It leverages logs from Cisco network devices configured with First Hop Security measures like RA Guard and DHCP Guard. This activity is significant as it can indicate attempts to compromise network integrity and security. If confirmed malicious, attackers could manipulate network traffic, leading to potential data interception, unauthorized access, or network disruption.
T1200,T1498,T1557,T1557.002 - Detect Outbound LDAP Traffic source: The following analytic identifies outbound LDAP traffic to external IP addresses. It leverages the Network_Traffic data model to detect connections on ports 389 or 636 that are not directed to private IP ranges (RFC1918). This activity is significant because outbound LDAP traffic can indicate potential data exfiltration or unauthorized access attempts. If confirmed malicious, attackers could exploit this to access sensitive directory information, leading to data breaches or further network compromise.
T1059,T1190 - Detect Outbound SMB Traffic source medium: The following analytic detects outbound SMB (Server Message Block) connections from internal hosts to external servers. It identifies this activity by monitoring network traffic for SMB requests directed towards the Internet, which are unusual for standard operations. This detection is significant for a SOC as it can indicate an attacker's attempt to retrieve credential hashes through compromised servers, a key step in lateral movement and privilege escalation. If confirmed malicious, this activity could lead to unauthorized access to sensitive data and potential full system compromise.
T1071,T1071.002 - Detect Port Security Violation source medium: The following analytic detects port security violations on Cisco switches. It leverages logs from Cisco network devices, specifically looking for events with mnemonics indicating port security violations. This activity is significant because it indicates an unauthorized device attempting to connect to a secured port, potentially bypassing network access controls. If confirmed malicious, this could allow an attacker to gain unauthorized access to the network, leading to data exfiltration, network disruption, or further lateral movement within the environment.
T1200,T1498,T1557,T1557.002 - Detect Rogue DHCP Server source medium: The following analytic identifies the presence of unauthorized DHCP servers on the network. It leverages logs from Cisco network devices with DHCP Snooping enabled, specifically looking for events where DHCP leases are issued from untrusted ports. This activity is significant because rogue DHCP servers can facilitate Man-in-the-Middle attacks, leading to potential data interception and network disruption. If confirmed malicious, this could allow attackers to redirect network traffic, capture sensitive information, and compromise the integrity of the network.
T1200,T1498,T1557 - Detect Traffic Mirroring source medium: The following analytic detects the initiation of traffic mirroring sessions on Cisco network devices. It leverages logs with specific mnemonics and facilities related to traffic mirroring, such as "ETH_SPAN_SESSION_UP" and "PKTCAP_START." This activity is significant because adversaries may use traffic mirroring to exfiltrate data by duplicating and forwarding network traffic to an external destination. If confirmed malicious, this could allow attackers to capture sensitive information, monitor network communications, and potentially compromise the integrity and confidentiality of the network.
T1020,T1020.001,T1200,T1498 - Internal Horizontal Port Scan source medium: This analytic identifies instances where an internal host has attempted to communicate with 250 or more destination IP addresses using the same port and protocol. Horizontal port scans from internal hosts can indicate reconnaissance or scanning activities, potentially signaling malicious intent or misconfiguration. By monitoring network traffic logs, this detection helps detect and respond to such behavior promptly, enhancing network security and preventing potential threats.
T1046 - Internal Horizontal Port Scan NMAP Top 20 source medium: This analytic identifies instances where an internal host has attempted to communicate with 250 or more destination IP addresses using on of the NMAP top 20 ports. Horizontal port scans from internal hosts can indicate reconnaissance or scanning activities, potentially signaling malicious intent or misconfiguration. By monitoring network traffic logs, this detection helps detect and respond to such behavior promptly, enhancing network security and preventing potential threats.
T1046 - Internal Vertical Port Scan source medium: This analytic detects instances where an internal host attempts to communicate with over 500 ports on a single destination IP address. It includes filtering criteria to exclude applications performing scans over ephemeral port ranges, focusing on potential reconnaissance or scanning activities. Monitoring network traffic logs allows for timely detection and response to such behavior, enhancing network security by identifying and mitigating potential threats promptly.
T1046 - Prohibited Network Traffic Allowed source medium: The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the "lookup_interesting_ports" table, is allowed. It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies. This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration. If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization's security posture.
T1048 - Protocol or Port Mismatch source low: The following analytic identifies network traffic where the higher layer protocol does not match the expected port, such as non-HTTP traffic on TCP port 80. It leverages data from network traffic inspection technologies like Bro or Palo Alto Networks firewalls. This activity is significant because it may indicate attempts to bypass firewall restrictions or conceal malicious communications. If confirmed malicious, this behavior could allow attackers to evade detection, maintain persistence, or exfiltrate data through commonly allowed ports, posing a significant threat to network security.
T1048,T1048.003 - Protocols passing authentication in cleartext source low: The following analytic identifies the use of cleartext protocols that risk leaking sensitive information. It detects network traffic on legacy protocols such as Telnet (port 23), POP3 (port 110), IMAP (port 143), and non-anonymous FTP (port 21). The detection leverages the Network_Traffic data model to identify TCP traffic on these ports. Monitoring this activity is crucial as it can expose credentials and other sensitive data to interception. If confirmed malicious, attackers could capture authentication details, leading to unauthorized access and potential data breaches.
- TOR Traffic source medium: The following analytic identifies allowed network traffic to The Onion Router (TOR), an anonymity network often exploited for malicious activities. It leverages data from Next Generation Firewalls, using the Network_Traffic data model to detect traffic where the application is TOR and the action is allowed. This activity is significant as TOR can be used to bypass conventional monitoring, facilitating hacking, data breaches, and illicit content dissemination. If confirmed malicious, this could lead to unauthorized access, data exfiltration, and severe compliance violations, compromising the integrity and security of the network.
T1090,T1090.003
Product-Filtered Rules
These rules use generic transport telemetry with a product-specific filter for Cisco Network Security.Kusto #
T1046, T1498T1046, T1498
Compatible Rules
These rules declare Cisco Network Security connector or schema compatibility without a product-specific query filter.Kusto #
T1546T1030, T1046, T1071, T1095, T1210T1078T1041, T1048T1059, T1095, T1190, T1203T1059, T1095, T1190, T1203T1496T1048T1003, T1071T1499T1008, T1568T1071T1071T1071T1071T1046, T1590T1046T1568T1071, T1571T1008, T1568T1566T1030T1071T1071T1071T1071T1071T1071T1030T1030