kevmap

Log sources › networkdevice:config

networkdevice:config

Inverted view: what can be detected if this is the log you have. Network Devices

14
channels
14
analytics
14
techniques
6
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Boot image path or firmware configuration variable modified outside of maintenance windows DC0004 Firmware Modification AN0276 1
Boot variable modified to point to non-standard or unsigned image DC0004 Firmware Modification AN0777 1
Configuration change events referencing encryption, TLS/SSL, or IPSec settings DC0061 File Modification AN0961 1
Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers DC0064 Command Execution AN1603 1
Configuration changes referencing 'crypto', 'key length', 'cipher', or downgrade of encryption settings DC0061 File Modification AN0681 1
Configuration changes referencing cryptographic hardware modules or disabling hardware acceleration DC0061 File Modification AN1360 1
Configuration changes referencing older image versions or unexpected boot parameters DC0061 File Modification AN1570 1
Configuration changes to boot variables, startup image paths, or checksum verification failures DC0061 File Modification AN0482 1
Configuration changes to startup image paths, boot loader parameters, or debug flags DC0061 File Modification AN1293 1
Configuration file modified or replaced on network device DC0061 File Modification AN0826 1
Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor) DC0004 Firmware Modification AN0497 1
NAT table modification (add/update/delete rule) DC0085 Network Traffic Content AN0465 1
config-change: timezone or ntp server configuration change after a time query command DC0061 File Modification AN0434 1
write: Startup configuration changes disabling security checks DC0041 Service Metadata AN1374 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1124 System Time Discoverydiscovery30
T1542 Pre-OS Bootstealth, persistence00
T1542.001 System Firmwarestealth, persistence20
T1542.004 ROMMONkitstealth, persistence00
T1542.005 TFTP Bootstealth, persistence01
T1557 Adversary-in-the-Middlecredential access, collection104
T1599.001 Network Address Translation Traversaldefense impairment10
T1600 Weaken Encryptiondefense impairment00
T1600.001 Reduce Key Spacedefense impairment00
T1600.002 Disable Crypto Hardwaredefense impairment00
T1601 Modify System Imagedefense impairment01
T1601.001 Patch System Imagedefense impairment00
T1601.002 Downgrade System Imagedefense impairment00
T1685 Disable or Modify Toolsdefense impairment1640

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2017-6742Cisco IOS and IOS XE Software T1542.005 Mapped
CVE-2019-5591Fortinet FortiOS T1557 Mapped
CVE-2021-44168Fortinet FortiOS T1601 Mapped
CVE-2022-1040Sophos Firewall T1557 Mapped
CVE-2025-31200Apple Multiple Products T1557 Stale
CVE-2025-31201Apple Multiple Products T1557 Stale