AN0758
Analytic 0758
Network Devices
Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.
networkconfig
unexpected OS image file upload or modification events
network:auth
repeated successful authentications with previously unknown accounts or anomalous password acceptance
[BaselineChecksums]
Trusted baseline cryptographic hashes for OS images, used to detect unauthorized modifications.
[AuthFailureThreshold]
Threshold for correlating unusual authentication successes following failed attempts or unknown account use.
[VerificationInterval]
Frequency of runtime OS image and memory integrity checks.