Cisco AAA: Detection of 'show history' and 'show logging' command input

Alerts on Cisco AAA command input attempting to view history or logging via 'show history'/'show logging' commands.

FreeReviewedSigma · Medium · v2
Product
cisco
Service
aaa
Author
Austin Clark (SigmaHQ), DRL 1.1
Published
2019-08-11
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Cisco AAA activity where command input matches 'show history', 'show history all', or 'show logging'. These commands can reveal previously executed commands and logging information that may contain sensitive data, including credentials captured in command history. It relies on telemetry from Cisco AAA reflecting the entered CLI commands and keyword matching within that input.

Related detections2 linkedT1552.003 — drag to rearrange
macOS Process Creation: Command Line Access to Shell History Files
Linux: Command-Line Access to Shell History Files via execve
Cisco AAA: Detection of 'show history' and 'show logging' command input
Pivot detection · T1552.003 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.