Network Device Authentication

T1556.004

Sub-technique of T1556 Modify Authentication Process.View on attack.mitre.org

About this technique

Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.

Modify System Image may include implanted code to the operating system for network devices to provide access for adversaries using a specific password. The modification includes a specific password which is implanted in the operating system image via the patch. Upon authentication attempts, the inserted code will first check to see if the user input is the password. If so, access is granted. Otherwise, the implanted code will pass the credentials on for verification of potentially valid credentials.

Detection rules2

Rules on DetectionCode tagged with T1556.004.

Sigma1

RuleLevelLog source
Cisco Dot1x Disabledmediumcisco / NULL

Splunk1

RuleTypeRiskData source
Cisco ASA - AAA Policy TamperingAnomalyNULLCisco ASA Logs

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples3

Software3

Used byProcedure example
MalwareDRYHOOK

DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in.

MalwareSLOWPULSE

SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password.

MalwareSYNful Knock

SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device.

References1

  1. Mandiant - Synful Knock Open source
    Bill Hau, Tony Lee, Josh Homan. (2015, September 15). SYNful Knock - A Cisco router implant - Part I. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.