LoFP LoFP / commonly run by administrators

Techniques

Sample rules

Cisco Collect Data

Description

Collect pertinent data from the configuration files

Detection logic

condition: keywords
keywords:
- show running-config
- show startup-config
- show archive config
- more