Cisco Show Commands Input
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the use of sensitive show commands (show history, show history all, or show logging) on Cisco devices. These commands can reveal previously executed commands, user credentials, or device activity logs — making them valuable for reconnaissance by insiders or attackers who have gained access.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_CISCO_SHOW_COMMAND_EXECUTED" select Action1.HOSTNAME,Action1.TYPESOURCE,Action1.TYPEFACILITY,Action1.INTERFACE,Action1.COMMANDEXECUTED,Action1.USERNAME,Action1.MESSAGE
Detection
Execution Mode
realtime
Log Sources
Cisco
Author
Austin Clark


