kevmap

TechniquesT1201 › AN0461

AN0461 Analytic 0461

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Chain: (1) privileged CLI sessions run read-only commands that dump AAA/password policies (e.g., show aaa, show password-policy); (2) same account changes AAA or user DB shortly after. Use network device AAA/command accounting or syslog.</p>
Detects
T1201 Password Policy Discovery
Part of
DET0161 Password Policy Discovery – cross-platform behavior-chain analytics

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:syslogcmd='show aaa*' OR 'show running-config | include password|aaa' OR 'show aaa common-criteria policy all'DC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ApprovedNOCSourcesJump hosts permitted to run show commands.
DeviceTierHigher risk weight on edge/critical devices.