Cisco Network Config Credentials

Detects credentials and sensitive configuration directives in Cisco IOS/NX-OS configuration files, including enable passwords/secrets, SNMP community strings with write access, PAC keys, and NVRAM/LDAP authentication indicators. Mirrors Snaffler rule KeepNetConfigCreds.

Type
regex
Engine
boost_regex
Confidence
high
Confidence justification
High confidence: the combination of Cisco-specific IOS directives (enable secret, snmp-server community RW, pac key) with network infrastructure corroborative keywords (hostname, interface, ip route) makes false positives extremely unlikely outside genuine Cisco configuration files.
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth), Computer Fraud and Abuse Act, Computer Misuse Act 1990
Frameworks
CIS Controls, ISO 27001, NIST CSF
Data categories
credentials, network infrastructure, security
Scope
specific
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Unsupported

Pattern

enable\s+(?:password|secret)\s+\S

Corroborative evidence keywords

service password-encryption, hostname, interface, ip route, version 1, no ip domain-lookup, spanning-tree

Proximity: 300 characters

Should match

Should not match

Known false positives

Collections