LoFP LoFP / when remote authentication is in place, this should not change often

Techniques

Sample rules

Cisco Local Accounts

Description

Find local accounts being created or modified as well as remote authentication configurations

Detection logic

condition: keywords
keywords:
- username
- aaa