Cisco AAA local account and remote authentication changes

Flags Cisco AAA log events showing local username/account changes and remote authentication configuration updates.

FreeReviewedSigma · High · v2
Product
cisco
Service
aaa
Author
Austin Clark (SigmaHQ), DRL 1.1
Published
2019-08-12
Updated
2026-07-31
title: Cisco AAA local account and remote authentication changes
id: 0ba8a740-3581-405e-91b7-d36b3b3a3f46
status: test
description: Identifies events containing both the keywords 'username' and 'aaa' that indicate local account creation/modification and remote authentication configuration changes on Cisco systems. Attackers may alter local credentials or adjust AAA settings to gain persistence and enable unauthorized access. The rule relies on Cisco AAA telemetry where these keyword strings appear in the logged event details.
author: Austin Clark, Huntrule Team
date: 2019-08-12
modified: 2023-01-04
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1136.001
  - attack.t1098
logsource:
  product: cisco
  service: aaa
detection:
  keywords:
    - username
    - aaa
  condition: keywords
falsepositives:
  - When remote authentication is in place, this should not change often
level: high
license: DRL-1.1
related:
  - id: 6d844f0f-1c18-41af-8f19-33e7654edfc3
    type: derived
references:
  - https://github.com/SigmaHQ/sigma/blob/master/rules/network/cisco/aaa/cisco_cli_local_accounts.yml