Skip to content

Add detection rules for CISA/NSA/FBI advisory AA26-194A (FSB Center 16 router config theft via SNMP/TFTP) - #6145

Open
zachvessey16 wants to merge 1 commit into
SigmaHQ:masterfrom
zachvessey16:add-fsb-router-detection-rules
Open

Add detection rules for CISA/NSA/FBI advisory AA26-194A (FSB Center 16 router config theft via SNMP/TFTP)#6145
zachvessey16 wants to merge 1 commit into
SigmaHQ:masterfrom
zachvessey16:add-fsb-router-detection-rules

Conversation

@zachvessey16

Copy link
Copy Markdown

Summary of the Pull Request

Adds two detection rules covering the attack chain described in CISA/NSA/FBI joint advisory AA26-194A (Russian FSB Center 16 targeting network devices via SNMP configuration theft and TFTP exfiltration). One rule detects SNMP connection attempts consistent with the advisory's described weak-community-string abuse; the other detects outbound TFTP transfers from a management subnet, matching the config-exfil step described in the advisory.

Validation performed:

  • python tests/test_logsource.py — pass
  • python tests/test_rules.py — pass
  • sigma check --validation-config tests/sigma_cli_conf.yml — 0 errors, 0 issues
  • Converted both rules to Splunk SPL and Elastic Lucene/EQL via sigma-cli to confirm cross-SIEM conversion logic

Note: the SNMP rule originally targeted product: zeek/service: snmp, but SNMP isn't currently a registered Zeek service in the SigmaHQ taxonomy, so it uses the generic firewall category instead (matching on port/protocol rather than SNMP-specific fields). Open to feedback on this approach.

Changelog

new: Potential Network Device Configuration Theft via SNMP
new: Outbound TFTP Transfer from Network Device Management Segment

Example Log Event

N/A

@github-actions github-actions Bot added Rules Review Needed The PR requires review labels Jul 16, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Welcome @zachvessey16 👋

It looks like this is your first pull request on the Sigma rules repository!

Please read the SigmaHQ conventions to ensure your contribution adheres to best practices and includes all the necessary elements for a successful review.

Also check CONTRIBUTING.md for more information on how to contribute to the Sigma rules repository, specifically proper testing and validation of your rules.

Thanks again, and welcome to the Sigma community! 😃

If you want to engage more with the community for official support, general discussions or announcements:

👉 Join our Discord server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants