Edge/VPN Appliance LOTL Persistence: Config, Accounts, SSH Keys, Logging (T1133/
This rule monitors network device audit logs for suspicious activities that indicate potential persistence or defense evasion on edge/VPN/router appliances. It specifically flags configuration changes, creation of new administrative accounts, addition of unauthorized SSH keys, and the disabling of logging/syslog export, which are common tactics for maintainig unauthorized access on network infrastructure.
Microsoft Sentinel (KQL)

