Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0272 — Detect Modification of Network Device Authentication via Patched System Images
DET0272

Detect Modification of Network Device Authentication via Patched System Images

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0758 Analytic 0758
Network Devices

Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.

networkconfig unexpected OS image file upload or modification events network:auth repeated successful authentications with previously unknown accounts or anomalous password acceptance
[BaselineChecksums] Trusted baseline cryptographic hashes for OS images, used to detect unauthorized modifications.
[AuthFailureThreshold] Threshold for correlating unusual authentication successes following failed attempts or unknown account use.
[VerificationInterval] Frequency of runtime OS image and memory integrity checks.

Detected Techniques

1

Details

MITRE ID
DET0272
STIX ID
x-mitre-detection-strategy--8a9ce0df-e256-4739-8db5-3e850e102e48
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.