Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0453 — Detection Strategy for SNMP (MIB Dump) on Network Devices
DET0453

Detection Strategy for SNMP (MIB Dump) on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1249 Analytic 1249
Network Devices

Defenders may observe suspicious SNMP MIB enumeration through abnormal queries for large sets of OIDs, repeated SNMP GETBULK/GETNEXT requests, or queries originating from non-administrative IP addresses. Anomalous use of community strings, authentication failures, or enumeration activity outside maintenance windows may also indicate attempts to dump MIB contents. Correlation across syslog, NetFlow, and SNMP audit data can reveal chains of behavior such as repeated authentication failures followed by successful large-scale OID retrieval.

networkdevice:syslog Authentication failures, unexpected community string usage, or unauthorized SNMPv1/v2 requests NSM:Flow High-volume or repeated SNMP GETBULK/GETNEXT queries from untrusted or external IPs networkdevice:audit SNMP configuration changes, such as enabling read/write access or modifying community strings
[AuthorizedAdminIPs] Expected IP ranges allowed to query SNMP. Deviation indicates possible misuse.
[NormalSNMPQueryRate] Baseline frequency and volume of SNMP queries; anomalies above threshold may indicate dumping.
[CommunityStringPatterns] Expected community strings (e.g., hashed or custom values). Unrecognized strings may signal abuse.
[TimeWindow] Time periods during which SNMP queries are authorized. Queries outside these hours may be malicious.

Detected Techniques

1

Details

MITRE ID
DET0453
STIX ID
x-mitre-detection-strategy--2dc6a789-2dd7-4d64-be82-73db6fc3fb70
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.