Cisco Network Device 802.1X (dot1x) Disabled via port-control Force-Authorized

Alerts on Cisco configuration changes that disable 802.1X on a port (force-authorized or no dot1x port-control).

FreeReviewedSigma · Medium · v2
Product
cisco
Service
aaa
Author
Luc Génaux (SigmaHQ), DRL 1.1
Published
2026-04-28
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule matches Cisco AAA/service CLI command strings used to disable IEEE 802.1X (dot1x) on an interface by forcing the port into an authorized state without 802.1X authentication. Disabling dot1x bypasses Network Access Control and can enable unauthorized devices to gain access to internal networks. The detection relies on telemetry that records the relevant Cisco command text, specifically variations of port-control force-authorized and dot1x/global disable commands.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.