AN1476
Analytic 1476
Windows
Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.
WinEventLog:Microsoft-Windows-WLAN-AutoConfig
EventCode=8001, 8002, 8003
WinEventLog:Security
EventCode=4776, 4625
[KnownSSIDList]
Defines approved Wi-Fi SSIDs for the environment; deviations may indicate malicious connection attempts.
[GeoLocationContext]
Correlates expected physical location of systems with observed Wi-Fi connections to detect anomalies.
AN1477
Analytic 1477
Linux
Detects unauthorized wireless associations by monitoring wpa_supplicant logs, NetworkManager events, and system calls related to interface state changes. Anomalies include repeated association failures, new SSIDs outside baselined values, and rogue AP connections.
linux:syslog
New Wi-Fi connection established or repeated association failures
auditd:SYSCALL
ioctl: Changes to wireless network interfaces (up, down, reassociate)
[AllowedSSIDRegex]
Regex-based whitelist of corporate SSIDs; anomalous matches indicate suspicious activity.
[RetryThreshold]
Number of failed association attempts allowed before triggering detection.
AN1478
Analytic 1478
macOS
Detects unauthorized Wi-Fi associations and SSID scanning activity using unified logs and airport command telemetry. Anomalies include rapid SSID switching, connections to unapproved SSIDs, or repeated authentication failures.
macos:unifiedlog
Association and authentication events including failures and new SSIDs
macos:osquery
query: Historical list of associated SSIDs compared against baseline
[BaselineSSIDHistory]
Historical record of corporate SSID associations per device; deviations may indicate rogue AP usage.
AN1479
Analytic 1479
Network Devices
Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points.
NSM:Firewall
rule_modification: New or modified firewall rules related to wireless interfaces
WIDS:AssociationLogs
Unauthorized AP or anomalous MAC address connection attempts
[AuthorizedAPList]
Defines known access points and MAC addresses; deviations highlight rogue or unauthorized devices.