Cisco AAA Command Output Collection: show running/startup-config and archive config

Detects Cisco command strings attempting to collect device configuration via show running/startup/archived config.

FreeReviewedSigma · Low · v2
Product
cisco
Service
aaa
Author
Austin Clark (SigmaHQ), DRL 1.1
Published
2019-08-11
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Cisco AAA activity where command output appears to be collected using configuration-display commands such as “show running-config”, “show startup-config”, and “show archive config”. Attackers can use these commands to inventory device configuration, identify services and credentials, and support subsequent access or lateral movement. It relies on AAA telemetry that records the observed command text, matching the listed keywords.

Related detections9 linkedT1552.001 — drag to rearrange
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Access to Cloud and Database Credential Files via Process
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)
Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious Double Base64 Decoded Payload Piped to Shell in CI (reviewdog Supply Chain)
Cisco AAA Command Output Collection: show running/startup-config and archive config
Pivot detection · T1552.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.