LoFP LoFP / legitimate administrators may run these commands

Techniques

Sample rules

Cisco Modify Configuration

Description

Modifications to a config that will serve an adversary’s impacts or persistence

Detection logic

condition: keywords
keywords:
- ip http server
- ip https server
- kron policy-list
- kron occurrence
- policy-list
- access-list
- ip access-group
- archive maximum

Cisco Clear Logs

Description

Clear command history in network OS which is used for defense evasion

Detection logic

condition: keywords
keywords:
- clear logging
- clear archive