Name:Cisco ASA - Reconnaissance Command Activity id:6e9d4f7a-3c8b-4a9e-8d2f-7b5c9e1a6f3d version:5 date:None author:Nasreddine Bencherchali, Splunk status:production type:Anomaly Description:This analytic detects potential reconnaissance activities on Cisco ASA devices by identifying execution of multiple information-gathering "show" commands within a short timeframe.
Adversaries who gain initial access to network infrastructure devices typically perform systematic reconnaissance to understand the device configuration, network topology, security policies, connected systems, and potential attack paths. This reconnaissance phase involves executing multiple "show" commands to enumerate device details, running configurations, active connections, routing information, and VPN sessions.
The detection monitors for command execution events (message ID 111009) containing reconnaissance-oriented "show" commands (such as show running-config, show version, show interface, show crypto, show conn, etc.) and triggers when 7 or more distinct reconnaissance commands are executed within a 5-minute window by the same user.
Investigate reconnaissance bursts from non-administrative accounts, unusual source IP addresses, activity during off-hours, methodical command sequences suggesting automated enumeration, or reconnaissance activity correlated with other suspicious behaviors.
We recommend adapting the detection filters to exclude known legitimate administrative activities.
Data_source:
``` Normalize command variations to base command types to count distinct reconnaissance categories. For example, "show running-config", "show running-config | include username", and "show running-config interface" all count as one command type. This prevents adversaries from evading detection by adding arguments or using multiple variations of the same command. ```
| stats count earliest(_time) as firstTime latest(_time) as lastTime dc(command_type) as unique_recon_commands values(command_type) as command_types values(command) as commands values(src_ip) as src_ip values(message_id) as message_id values(action) as action by _time host user
how_to_implement:This search requires Cisco ASA syslog data to be ingested into Splunk via the Cisco Security Cloud TA.
To ensure this detection works effectively, configure your ASA and FTD devices to generate and forward message ID 111009.
If your logging level is set to 'Debugging', these messages should already be included, else we recommend setting an event list that keeps the severity level you are using and adds message ID 111009.
You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html.
You can also change the severity level of the above message id's to the syslog level you have currently enabled using the logging message syslog_id level severity_level command in global configuration mode. For more information, see Change the Severity Level of a Syslog Message : https://www.cisco.com/c/en/us/td/docs/security/asa/asa922/configuration/general/asa-922-general-config/monitor-syslog.html#ID-2121-000006da
known_false_positives:Legitimate sequences occur during troubleshooting, health checks, upgrades, audits, or automation scripts. Verify against change management.
Filter known admin accounts, trusted management stations, or adjust threshold based on baseline.
References: -https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/sa-shov-commands.html drilldown_searches: name:'View the detection results for $host$ and $user$' search:'%original_detection_search% | search host = $host$ user = $user$' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for $host$' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ($host$) | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Suspicious Cisco Adaptive Security Appliance Activity']