Suspicious Cisco IOS XE Privileged Account Creation via CVE-2023-20198

PremiumReviewedSigma · High · v1
Product
cisco
Service
aaa
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of the privileged local accounts cisco_tac_admin and cisco_support that are dropped when the Cisco IOS XE Web UI is exploited through CVE-2023-20198. These account names are strong campaign specific indicators of unauthorized administrative access and should be treated as a compromise of the network device.

Related detections9 linkedT1190 — drag to rearrange
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Possible FortiWeb Authentication Bypass via Path Traversal to fwbcgi (via webserver)
Suspicious DNS Query To Interactsh OAST Domain
Suspicious SmarterMail Force Password Reset API Request Indicating Account Takeover
Possible CrushFTP CVE-2025-31161 Authentication Bypass via Webserver
Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious Cisco IOS XE Privileged Account Creation via CVE-2023-20198
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.