kevmap

TechniquesT1059.004 › AN1084

AN1084 Analytic 1084

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects Unix shell usage on network appliances (e.g., routers, firewalls, embedded Linux) through rare console commands, CLI interfaces, or script injection via exposed APIs or SSH.</p>
Detects
T1059.004 Unix Shell
Part of
DET0384 Behavioral Detection of Unix Shell Execution

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:syslogCLI Command AuditDC0064 Command Execution
NSM:Flowremote accessDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
InterfaceFlags command line access via remote console (telnet/SSH/API) from non-whitelisted source.
CommandStringMonitors rare/privileged shell commands (e.g., enable, tftp, firmware mod).

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2016-10033PHP PHPMailerMapped
CVE-2019-0708Microsoft Remote Desktop ServicesMapped
CVE-2021-36380Sunhillo SureLineMapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2023-38831RARLAB WinRARMapped
CVE-2023-39780ASUS RT-AX55 RoutersMapped
CVE-2023-44221SonicWall SMA100 AppliancesMapped
CVE-2023-46604Apache ActiveMQMapped
CVE-2024-24919Check Point Quantum Security GatewaysMapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS)Mapped
CVE-2025-25257Fortinet FortiWebMapped