EXPLORE
← Back to Explore
T1557

Adversary-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or replay attacks ([Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212)). By abusing features of common networking protocols that can determine the flow of ...

LinuxmacOSNetwork DevicesWindows
32
Detections
4
Sources
3
Threat Actors

BY SOURCE

18elastic10sigma2kql2splunk_escu

PROCEDURES (26)

Brute Force3 detections

Auto-extracted: 3 detections for brute force

Network Connection Monitoring2 detections

Auto-extracted: 2 detections for network connection monitoring

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Token2 detections

Auto-extracted: 2 detections for token

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Http1 detections

Auto-extracted: 1 detections for http

Remote1 detections

Auto-extracted: 1 detections for remote

Script Execution Monitoring1 detections

Auto-extracted: 1 detections for script execution monitoring

Remote1 detections

Auto-extracted: 1 detections for remote

Cloud1 detections

Auto-extracted: 1 detections for cloud

Cloud1 detections

Auto-extracted: 1 detections for cloud

Base641 detections

Auto-extracted: 1 detections for base64

Kerbero1 detections

Auto-extracted: 1 detections for kerbero

Base641 detections

Auto-extracted: 1 detections for base64

Credential1 detections

Auto-extracted: 1 detections for credential

Lateral1 detections

Auto-extracted: 1 detections for lateral

Phish1 detections

Auto-extracted: 1 detections for phish

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Credential1 detections

Auto-extracted: 1 detections for credential

Credential1 detections

Auto-extracted: 1 detections for credential

Lateral1 detections

Auto-extracted: 1 detections for lateral

Phish1 detections

Auto-extracted: 1 detections for phish

Brute Force1 detections

Auto-extracted: 1 detections for brute force

Service1 detections

Auto-extracted: 1 detections for service

Process Creation Monitoring1 detections

Auto-extracted: 1 detections for process creation monitoring

Dns1 detections

Auto-extracted: 1 detections for dns

DETECTIONS (32)

AWS Route 53 Private Hosted Zone Associated With a VPC
elasticmedium
Azure Sign-In With Axios User Agent
sigmalow
Cisco ASA - Packet Capture Activity
splunk_escu
Cisco BGP Authentication Failures
sigmalow
Cisco LDP Authentication Failures
sigmalow
Creation of a DNS-Named Record
elasticlow
Creation or Modification of Root Certificate
elasticlow
Detect Rogue DHCP Server
splunk_escu
DNS Global Query Block List Modified or Disabled
elasticmedium
Google Workspace Device Registration Burst for Single User
elasticmedium
Google Workspace User Login with Unusual ASN
elasticlow
Huawei BGP Authentication Failures
sigmalow
ISATAP Router Address Was Set
sigmamedium
Juniper BGP Missing MD5
sigmalow
Notepad++ Updater DNS Query to Uncommon Domains
sigmamedium
Potential ADIDNS Poisoning via Wildcard Record Creation
elastichigh
Potential Adversary in the middle Phishing
kql
Potential Computer Account NTLM Relay Activity
elasticmedium
Potential Kerberos Coercion via DNS-Based SPN Spoofing
elastichigh
Potential Kerberos Relay Attack against a Computer Account
elastichigh
Potential Kerberos SPN Spoofing via Suspicious DNS Query
elastichigh
Potential Local NTLM Relay via HTTP
elastichigh
Potential Machine Account Relay Attack via SMB
elastichigh
Potential NTLM Relay Attack against a Computer Account
elastichigh
Potential PowerShell Pass-the-Hash/Relay Script
elastichigh
Potential Suspicious Activity Using SeCEdit
sigmamedium
Potential WPAD Spoofing via DNS Record Creation
elasticmedium
Service Creation via Local Kerberos Authentication
elastichigh
Storm-0539 AiTM URLs - EmailEvents
kql
Suspicious Child Process of Notepad++ Updater - GUP.Exe
sigmahigh
Uncommon File Created by Notepad++ Updater Gup.EXE
sigmahigh
WebProxy Settings Modification
elasticmedium