Cisco AAA keyword hits for data staging and file transfer commands (TFTP/RCP/PUT/COPY/ARCHIVE)
Flags Cisco AAA activity containing TFTP/RCP and copy/archive commands commonly used to stage data on devices.
- Product
- cisco
- Service
- aaa
- Author
- Austin Clark (SigmaHQ), DRL 1.1
- Published
- 2019-08-12
- Updated
- 2026-07-31
ATT&CK techniques
Collection → C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Exfiltration
Impact
What it detects
This rule flags Cisco AAA logs that contain specific keywords associated with staging data onto or off a device, including TFTP/RCP usage and commands like PUT/COPY, configuration replace, and archive tar. Attackers may use these operations to move files for exfiltration, infiltration, or lateral movement by staging payloads or configuration changes. Detection relies on text matches of the listed keywords in Cisco AAA telemetry.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Cisco AAA keyword hits for data staging and file transfer commands (TFTP/RCP/PUT/COPY/ARCHIVE)
id: 70746874-8249-410a-8704-04d188d5108d
status: test
description: This rule flags Cisco AAA logs that contain specific keywords associated with staging data onto or off a device, including TFTP/RCP usage and commands like PUT/COPY, configuration replace, and archive tar. Attackers may use these operations to move files for exfiltration, infiltration, or lateral movement by staging payloads or configuration changes. Detection relies on text matches of the listed keywords in Cisco AAA telemetry.
author: Austin Clark, Huntrule Team
date: 2019-08-12
modified: 2023-01-04
tags:
- attack.collection
- attack.lateral-movement
- attack.command-and-control
- attack.exfiltration
- attack.t1074
- attack.t1105
- attack.t1560.001
logsource:
product: cisco
service: aaa
detection:
keywords:
- tftp
- rcp
- puts
- copy
- configure replace
- archive tar
condition: keywords
falsepositives:
- Generally used to copy configs or IOS images
level: low
license: DRL-1.1
related:
- id: 5e51acb2-bcbe-435b-99c6-0e3cd5e2aa59
type: derived
references:
- https://github.com/SigmaHQ/sigma/blob/master/rules/network/cisco/aaa/cisco_cli_moving_data.yml