Cross-source coverage
T1557 / ATT&CK
Adversary-in-the-Middle
66 rules across 8 sources.
Showing atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.
Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.
- Tactics
- Credential Access · Collection
- Platforms
- Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlognetworkdevice:config
How MITRE says to detect it DET0296
Detect Adversary-in-the-Middle via Network and Configuration Anomalies
Windows Analytic 0823
Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.
WinEventLog:SecurityEventCode=4663, 4670, 4656WinEventLog:SysmonEventCode=3, 22
Linux Analytic 0824
Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.
auditd:SYSCALLopen, writeNSM:FlowUnexpected ARP replies or DNS responses inconsistent with authoritative servers
macOS Analytic 0825
Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.
macos:unifiedlogConfiguration profile modified or new profile installedNSM:FlowTLS downgrade or inconsistent DNS answers
Network Devices Analytic 0826
Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.
NSM:FlowUnexpected route changes or duplicate gateway advertisementsnetworkdevice:configConfiguration file modified or replaced on network device
Sub-techniques with coverage
Counted in the 66 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
25 rules| Detection | Severity | Format |
|---|---|---|
| Google Workspace Impossible Travel Login | High | Elastic TOML |
| ICMP Redirect Message from Internal Host | High | Elastic TOML |
| Microsoft Entra ID Impossible Travel Sign-in | High | Elastic TOML |
| Multiple DHCP Servers Responding to the Same Transaction | High | Elastic TOML |
| Potential ADIDNS Poisoning via Wildcard Record Creation | High | Elastic TOML |
| Potential Kerberos Coercion via DNS-Based SPN Spoofing | High | Elastic TOML |
| Potential Kerberos Relay Attack against a Computer Account | High | Elastic TOML |
| Potential Kerberos SPN Spoofing via Suspicious DNS Query | High | Elastic TOML |
| Potential Local NTLM Relay via HTTP | High | Elastic TOML |
| Potential Machine Account Relay Attack via SMB | High | Elastic TOML |
+ 15 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
21 rules| Detection | Severity | Format |
|---|---|---|
| Potential SMB Relay Attack Tool Execution | Critical | Sigma |
| Attempts of Kerberos Coercion Via DNS SPN Spoofing | High | Sigma |
| HackTool - ADCSPwn Execution | High | Sigma |
| HackTool - Impacket Tools Execution | High | Sigma |
| Local Privilege Escalation Indicator TabTip | High | Sigma |
| Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation | High | Sigma |
| RottenPotato Like Attack Pattern | High | Sigma |
| Suspicious Child Process of Notepad++ Updater - GUP.Exe | High | Sigma |
| Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing | High | Sigma |
| Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network | High | Sigma |
+ 11 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
10 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - Packet Capture Activity | Undefined | SPL |
| Detect ARP Poisoning | Undefined | SPL |
| Detect IPv6 Network Infrastructure Threats | Undefined | SPL |
| Detect Port Security Violation | Undefined | SPL |
| Detect Rogue DHCP Server | Undefined | SPL |
| DNS Kerberos Coercion | Undefined | SPL |
| Windows Credential Target Information Structure in Commandline | Undefined | SPL |
| Windows Kerberos Coercion via DNS | Undefined | SPL |
| Windows Short Lived DNS Record | Undefined | SPL |
| Windows Theme File Creation in Unusual Location | Undefined | SPL |
socfortress/Wazuh-Rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Powershell script: Network attack/C2 cmdlet detected | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Download Inveigh Script (T1557.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell GitHub Inveigh (T1557.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Inveigh Execution (T1557.001) | High | Wazuh XML |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Potential Adversary in the middle Phishing | Undefined | KQL |
| Storm-0539 AiTM URLs - EmailEvents | Undefined | KQL |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| A host is potentially running a hacking tool (ASIM Web Session schema) | Medium | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| MS-DHCP: Codes above 50 are used for Rogue Server Detection information. | High | Wazuh XML |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Packet socket created in container | Low | Falco YAML |