Cisco AAA Commands Indicating File Deletion on Local Flash Storage

Flags Cisco AAA log entries referencing flash file erase, delete, or format operations that may indicate stealthy cleanup.

FreeReviewedSigma · Medium · v2
Product
cisco
Service
aaa
Author
Austin Clark (SigmaHQ), DRL 1.1
Published
2019-08-12
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags Cisco AAA log events containing commands related to erasing, deleting, or formatting files on flash storage. Attackers may remove files to cover tracks, disrupt evidence collection, or reduce available artifacts on a device. The detection relies on keyword matches for erase, delete, and format within AAA service logs where such operator actions are recorded.

Related detections9 linkedT1070.004 — drag to rearrange
Suspicious sha256sum.exe Execution from Windows Temp Directory
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Self-Deletion via Ping Loopback Delay and Del Command
Suspicious Deletion of Explorer RunMRU Values
Suspicious PowerShell Self-Delete Of Executable via Process Creation
Suspicious Prefetch Deletion for Anti-Forensics
Malicious Ransomware Self-Deletion via Ping Loopback and Del
Cisco AAA Commands Indicating File Deletion on Local Flash Storage
Pivot detection · T1070.004 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.