Suspicious Cisco Denial of Service (via aaa)
This rule detects a system being shutdown or put into different boot mode
SigmamediumNetworkv1
sigma
suspicious-cisco-denial-of-service-via-aaa
title: Suspicious Cisco Denial of Service (via aaa)
id: 788fde63-ba25-5717-bed7-f8ab27cb20a9
status: stable
description: This rule detects a system being shutdown or put into different boot mode
author: Huntrule Team
date: 2026-01-03
tags:
- attack.impact
- attack.t1495
- attack.t1529
- attack.t1565.001
logsource:
product: cisco
service: aaa
detection:
keywords:
- 'shutdown'
- 'config-register 0x2100'
- 'config-register 0x2142'
condition: keywords
falsepositives:
- Unknown
level: medium
references:
- https://attack.mitre.org/techniques/T1565/001/
- https://attack.mitre.org/techniques/T1529/
- https://attack.mitre.org/techniques/T1495/
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.