kevmap

TechniquesT1040 › AN0879

AN0879 Analytic 0879

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects execution of capture commands via CLI (monitor capture, debug packet, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.</p>
Detects
T1040 Network Sniffing
Part of
DET0314 Detection Strategy for Network Sniffing Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:syslogadmin login eventsDC0002 User Account Authentication
networkdevice:syslogexec command='monitor capture'DC0064 Command Execution
networkdevice:syslogconfig change (e.g., logging buffered, pcap buffers)DC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AdminSessionDurationTunable alerting threshold for interactive CLI sessions.
CaptureCommandListDefine set of known capture/debug commands per vendor to flag unexpected usage.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-32030ASUS RoutersMapped
CVE-2022-1040Sophos FirewallMapped