Cross-source coverage

T1557 / ATT&CK

Adversary-in-the-Middle

63 rules across 8 sources.

3 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.

Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.

Platforms
Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlognetworkdevice:config

How MITRE says to detect it DET0296

Detect Adversary-in-the-Middle via Network and Configuration Anomalies

Windows Analytic 0823

Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.

  • WinEventLog:Security EventCode=4663, 4670, 4656
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0824

Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.

  • auditd:SYSCALL open, write
  • NSM:Flow Unexpected ARP replies or DNS responses inconsistent with authoritative servers

macOS Analytic 0825

Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.

  • macos:unifiedlog Configuration profile modified or new profile installed
  • NSM:Flow TLS downgrade or inconsistent DNS answers

Network Devices Analytic 0826

Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.

  • NSM:Flow Unexpected route changes or duplicate gateway advertisements
  • networkdevice:config Configuration file modified or replaced on network device

Sub-techniques with coverage

Counted in the 63 above — a rule tagged a sub-technique covers this technique too.


elastic/detection-rules

24 rules
Detection Severity Format
Google Workspace Impossible Travel Login High Elastic TOML
ICMP Redirect Message from Internal Host High Elastic TOML
Microsoft Entra ID Impossible Travel Sign-in High Elastic TOML
Multiple DHCP Servers Responding to the Same Transaction High Elastic TOML
Potential ADIDNS Poisoning via Wildcard Record Creation High Elastic TOML
Potential Kerberos Coercion via DNS-Based SPN Spoofing High Elastic TOML
Potential Kerberos Relay Attack against a Computer Account High Elastic TOML
Potential Local NTLM Relay via HTTP High Elastic TOML
Potential Machine Account Relay Attack via SMB High Elastic TOML
Potential NTLM Relay Attack against a Computer Account High Elastic TOML

+ 14 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

19 rules
Detection Severity Format
Potential SMB Relay Attack Tool Execution Critical Sigma
Attempts of Kerberos Coercion Via DNS SPN Spoofing High Sigma
HackTool - ADCSPwn Execution High Sigma
HackTool - Impacket Tools Execution High Sigma
Local Privilege Escalation Indicator TabTip High Sigma
Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation High Sigma
RottenPotato Like Attack Pattern High Sigma
Suspicious Child Process of Notepad++ Updater - GUP.Exe High Sigma
Uncommon File Created by Notepad++ Updater Gup.EXE High Sigma
WinDivert Driver Load High Sigma

+ 9 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

10 rules
Detection Severity Format
Cisco ASA - Packet Capture Activity Undefined SPL
Detect ARP Poisoning Undefined SPL
Detect IPv6 Network Infrastructure Threats Undefined SPL
Detect Port Security Violation Undefined SPL
Detect Rogue DHCP Server Undefined SPL
DNS Kerberos Coercion Undefined SPL
Windows Credential Target Information Structure in Commandline Undefined SPL
Windows Kerberos Coercion via DNS Undefined SPL
Windows Short Lived DNS Record Undefined SPL
Windows Theme File Creation in Unusual Location Undefined SPL

socfortress/Wazuh-Rules

4 rules
Detection Severity Format
Powershell script: Network attack/C2 cmdlet detected High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Download Inveigh Script (T1557.001) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell GitHub Inveigh (T1557.001) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Inveigh Execution (T1557.001) High Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Potential Adversary in the middle Phishing Undefined KQL
Storm-0539 AiTM URLs - EmailEvents Undefined KQL

Azure/Azure-Sentinel

1 rule
Detection Severity Format
A host is potentially running a hacking tool (ASIM Web Session schema) Medium KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
MS-DHCP: Codes above 50 are used for Rogue Server Detection information. High Wazuh XML

falcosecurity/rules

1 rule
Detection Severity Format
Packet socket created in container Low Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.