Cisco AAA local account and remote authentication changes

Flags Cisco AAA log events showing local username/account changes and remote authentication configuration updates.

FreeReviewedSigma · High · v2
Product
cisco
Service
aaa
Author
Austin Clark (SigmaHQ), DRL 1.1
Published
2019-08-12
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies events containing both the keywords 'username' and 'aaa' that indicate local account creation/modification and remote authentication configuration changes on Cisco systems. Attackers may alter local credentials or adjust AAA settings to gain persistence and enable unauthorized access. The rule relies on Cisco AAA telemetry where these keyword strings appear in the logged event details.

Related detections9 linkedT1136.001 — drag to rearrange
Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Suspicious Local Account Creation via Net User in Pre-Ransomware Phase
Suspicious Hidden Local Account Creation via Net User by UAT-8099
Malicious Local Account Creation of Support or Whiteninja via net.exe
Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
Malicious Cluster-Admin Role Binding Creation (via audit)
Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
Cisco AAA local account and remote authentication changes
Pivot detection · T1136.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.