Post-Auth Config Change on Network Appliance (3P)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Hunts for post-auth configuration tampering on Fortinet, Palo Alto, and Cisco appliances in CommonSecurityLog, including firewall policy weakening, local admin changes, auth updates, and VPN/routing/ACL modifications.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID 3d0ffd07-026f-44cf-9f60-8df51ba76690
Tactics DefenseEvasion, Persistence
Techniques T1562.004, T1136.001, T1098
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceEventClassID in "0100044547,111010,44547"
DeviceEventClassID == "CONFIG"
DeviceEventClassID has_any "111007,111008,111010"
DeviceProduct has_any "ASA,FTD,Firepower"
DeviceProduct startswith "FortiGate"
DeviceVendor in "Cisco,Fortinet,Palo Alto Networks"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity