Before the platforms, the telemetry protocols themselves are attackable. SNMP is the richest: a widely deployed, frequently weakly-authenticated protocol that reveals a device's entire state and, with write access, reconfigures it. Syslog is a trusting, usually unauthenticated ingestion path that an attacker spoofs, forges, and floods to poison the record operators and SIEMs rely on. And NetFlow/IPFIX collectors hold the map of who talks to whom across the network, valuable reconnaissance and a target for forged records. These are protocol-level attacks, independent of which platform consumes them.
Subtopics#
- SNMP: device data disclosure, weak community strings, and write-access abuse.
- Syslog: spoofing, injection, and flooding of the log stream.
- NetFlow and IPFIX: harvesting and forging network flow telemetry.