UAT-8616 Rogue Device Peering Registration in Cisco SD-WAN Fabric

Detects the unauthorized addition or peering of rogue devices within a Cisco SD-WAN fabric. This rule monitors vManage and vBond logs for successful peering or registration events that correlate with known rogue indicators, such as certificate validation failures, mismatching system information, or untrusted peer identities. This activity is often indicative of attackers attempting to gain persistent control over the SD-WAN infrastructure, potentially using authentication bypass vulnerabilities or stolen credentials.