Log sources › networkdevice:config
networkdevice:config
Inverted view: what can be detected if this is the log you have. Network Devices
14
channels
14
analytics
14
techniques
6
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Boot image path or firmware configuration variable modified outside of maintenance windows |
DC0004 Firmware Modification | AN0276 | 1 |
Boot variable modified to point to non-standard or unsigned image |
DC0004 Firmware Modification | AN0777 | 1 |
Configuration change events referencing encryption, TLS/SSL, or IPSec settings |
DC0061 File Modification | AN0961 | 1 |
Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers |
DC0064 Command Execution | AN1603 | 1 |
Configuration changes referencing 'crypto', 'key length', 'cipher', or downgrade of encryption settings |
DC0061 File Modification | AN0681 | 1 |
Configuration changes referencing cryptographic hardware modules or disabling hardware acceleration |
DC0061 File Modification | AN1360 | 1 |
Configuration changes referencing older image versions or unexpected boot parameters |
DC0061 File Modification | AN1570 | 1 |
Configuration changes to boot variables, startup image paths, or checksum verification failures |
DC0061 File Modification | AN0482 | 1 |
Configuration changes to startup image paths, boot loader parameters, or debug flags |
DC0061 File Modification | AN1293 | 1 |
Configuration file modified or replaced on network device |
DC0061 File Modification | AN0826 | 1 |
Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor) |
DC0004 Firmware Modification | AN0497 | 1 |
NAT table modification (add/update/delete rule) |
DC0085 Network Traffic Content | AN0465 | 1 |
config-change: timezone or ntp server configuration change after a time query command |
DC0061 File Modification | AN0434 | 1 |
write: Startup configuration changes disabling security checks |
DC0041 Service Metadata | AN1374 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1124 System Time Discovery | discovery | 3 | 0 |
| T1542 Pre-OS Boot | stealth, persistence | 0 | 0 |
| T1542.001 System Firmware | stealth, persistence | 2 | 0 |
| T1542.004 ROMMONkit | stealth, persistence | 0 | 0 |
| T1542.005 TFTP Boot | stealth, persistence | 0 | 1 |
| T1557 Adversary-in-the-Middle | credential access, collection | 10 | 4 |
| T1599.001 Network Address Translation Traversal | defense impairment | 1 | 0 |
| T1600 Weaken Encryption | defense impairment | 0 | 0 |
| T1600.001 Reduce Key Space | defense impairment | 0 | 0 |
| T1600.002 Disable Crypto Hardware | defense impairment | 0 | 0 |
| T1601 Modify System Image | defense impairment | 0 | 1 |
| T1601.001 Patch System Image | defense impairment | 0 | 0 |
| T1601.002 Downgrade System Image | defense impairment | 0 | 0 |
| T1685 Disable or Modify Tools | defense impairment | 164 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1542.005 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1557 | Mapped |
| CVE-2021-44168 | Fortinet FortiOS | T1601 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1557 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1557 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1557 | Stale |