Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0142 — Behavioral Detection of CLI Abuse on Network Devices
DET0142

Behavioral Detection of CLI Abuse on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0399 Analytic 0399
Network Devices

Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows.

networkdevice:syslog command_exec NSM:Flow remote CLI session detection networkdevice:syslog authorization/accounting logs
[TimeWindow] Config changes made outside of maintenance windows are more suspicious.
[UserContext] Unexpected CLI activity by service accounts or users not assigned to manage network devices.
[CommandPattern] Regex or keyword match on dangerous or unusual commands (e.g., 'no logging', 'reload', 'copy tftp', 'config replace').
[SourceIP] Remote CLI sessions originating from untrusted networks or jump hosts.
[SessionDuration] Abnormally short or long SSH/Telnet CLI sessions compared to baseline.

Detected Techniques

1

Details

MITRE ID
DET0142
STIX ID
x-mitre-detection-strategy--ca871237-8615-47b7-9981-92d1d920d346
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.