Detection rules › Sigma
Cisco Crypto Commands
Show when private keys are being exported from the device, or when new certificates are installed
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Defense Impairment | T1553.004 Subvert Trust Controls: Install Root Certificate |
| Credential Access | T1552.004 Unsecured Credentials: Private Keys |
Rule body yaml
title: Cisco Crypto Commands
id: 1f978c6a-4415-47fb-aca5-736a44d7ca3d
status: test
description: Show when private keys are being exported from the device, or when new certificates are installed
references:
- https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html
author: Austin Clark
date: 2019-08-12
modified: 2023-01-04
tags:
- attack.credential-access
- attack.defense-impairment
- attack.t1553.004
- attack.t1552.004
logsource:
product: cisco
service: aaa
detection:
keywords:
- 'crypto pki export'
- 'crypto pki import'
- 'crypto pki trustpoint'
condition: keywords
falsepositives:
- Not commonly run by administrators. Also whitelist your known good certificates
level: high
Stages and Predicates
Stage 0: condition
keywordsStage 1: keywords
keywords:
- 'crypto pki export'
- 'crypto pki import'
- 'crypto pki trustpoint'