Suspicious Cisco Denial of Service (via aaa)

This rule detects a system being shutdown or put into different boot mode

SigmamediumNetworkv1
sigma
title: Suspicious Cisco Denial of Service (via aaa)
id: 788fde63-ba25-5717-bed7-f8ab27cb20a9
status: stable
description: This rule detects a system being shutdown or put into different boot mode
author: Huntrule Team
date: 2026-01-03
tags:
    - attack.impact
    - attack.t1495
    - attack.t1529
    - attack.t1565.001
logsource:
    product: cisco
    service: aaa
detection:
    keywords:
        - 'shutdown'
        - 'config-register 0x2100'
        - 'config-register 0x2142'
    condition: keywords
falsepositives:
    - Unknown
level: medium
references:
    - https://attack.mitre.org/techniques/T1565/001/
    - https://attack.mitre.org/techniques/T1529/
    - https://attack.mitre.org/techniques/T1495/

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.