{"id":"T1556.004","name":"Network Device Authentication","url":"https://attack.mitre.org/techniques/T1556/004","tactics":["defense-impairment","persistence","credential-access"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0272","stix_id":"x-mitre-detection-strategy--8a9ce0df-e256-4739-8db5-3e850e102e48","name":"Detect Modification of Network Device Authentication via Patched System Images","url":"https://attack.mitre.org/detectionstrategies/DET0272","analytics":[{"id":"AN0758","stix_id":"x-mitre-analytic--2f39584b-59bd-43ec-bd0a-5c2eba258ae2","name":"Analytic 0758","description":"Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.","url":"https://attack.mitre.org/detectionstrategies/DET0272#AN0758","platforms":["Network Devices"],"log_source_references":[{"name":"networkconfig","channel":"unexpected OS image file upload or modification events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkconfig"},{"name":"network:auth","channel":"repeated successful authentications with previously unknown accounts or anomalous password acceptance","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"network-auth"}],"mutable_elements":[{"field":"BaselineChecksums","description":"Trusted baseline cryptographic hashes for OS images, used to detect unauthorized modifications."},{"field":"AuthFailureThreshold","description":"Threshold for correlating unusual authentication successes following failed attempts or unknown account use."},{"field":"VerificationInterval","description":"Frequency of runtime OS image and memory integrity checks."}],"live":true,"detection_strategies":["DET0272"],"techniques":["T1556.004"]}],"live":true,"version":"1.0","techniques":["T1556.004"]}],"sigma_rules":[{"id":"ef0ff092-a24a-4fbc-beea-06c08d53e085","title":"Cisco Dot1x Disabled","author":"Luc Génaux","status":"experimental","level":"medium","date":"2026-04-28","modified":null,"description":"Detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface.\nDisabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network.\nThis activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.\n","references":["https://www.cisco.com/en/US/docs/ios-xml/ios/san/command/san-xe-3se-3850-cr-book_chapter_00.html#wp3394428680","https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-xe-3se-3850-cr-book/sec-a1-xe-3se-3850-cr-book_chapter_010.html#wp3502072400","https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_53_se/command/reference/2960ComRef/cli1.html#47220"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1685","attack.t1556.004"],"path":"rules/network/cisco/aaa/cisco_cli_dot1x_disabled.yml","techniques":["T1685","T1556.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}