{"id":"T1059.008","name":"Network Device CLI","url":"https://attack.mitre.org/techniques/T1059/008","tactics":["execution"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0142","stix_id":"x-mitre-detection-strategy--ca871237-8615-47b7-9981-92d1d920d346","name":"Behavioral Detection of CLI Abuse on Network Devices","url":"https://attack.mitre.org/detectionstrategies/DET0142","analytics":[{"id":"AN0399","stix_id":"x-mitre-analytic--3dc28690-699a-4f6d-ad4b-278aa2dd8c59","name":"Analytic 0399","description":"Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows.","url":"https://attack.mitre.org/detectionstrategies/DET0142#AN0399","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"command_exec","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"remote CLI session detection","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"networkdevice:syslog","channel":"authorization/accounting logs","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"TimeWindow","description":"Config changes made outside of maintenance windows are more suspicious."},{"field":"UserContext","description":"Unexpected CLI activity by service accounts or users not assigned to manage network devices."},{"field":"CommandPattern","description":"Regex or keyword match on dangerous or unusual commands (e.g., 'no logging', 'reload', 'copy tftp', 'config replace')."},{"field":"SourceIP","description":"Remote CLI sessions originating from untrusted networks or jump hosts."},{"field":"SessionDuration","description":"Abnormally short or long SSH/Telnet CLI sessions compared to baseline."}],"live":true,"detection_strategies":["DET0142"],"techniques":["T1059.008"]}],"live":true,"version":"1.0","techniques":["T1059.008"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}