// MITRE ATT&CK

T1059.008 · Network Device CLI

🎯 Execution Network Devices Sub-técnica

Sub-técnica de T1059 · Command and Scripting Interpreter.

Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads. The CLI is the primary means through which users and administrators interact with the device in order to view system information, modify device operations, or per...

¿Cómo detectarlo y mitigarlo?

La detección de Network Device CLI parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.