If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1040 - Network Sniffing, Technique T1.

site address: attack.mitre.org/techniques/T1040 redirected to: attack.mitre.org/techniques/T1040

site title: Network Sniffing, Technique T1040 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 21 August 2026 20:22:48 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

network, sniffing, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
and (44), the (43), retrieved (40), network (40), traffic (28), for (18), march (17), #sniffing (15), packet (15), all (14), used (14), capture (14), may (13), data (12), has (11), can (11), att (10), 2025 (10), use (9), techniques (9), 2024 (9), april (9), 2020 (9), 2019 (9), credentials (9), october (8), 2022 (8), mirroring (8), access (8), that (8), sniff (8), enterprise (7), august (7), team (7), devices (7), monitor (7), from (7), name (7), over (7), june (6), espionage (6), 2018 (6), 2021 (6), such (6), sent (6), 2015 (5), 2026 (5), ics (5), mobile (5), none (5), unc3886 (5), january (5), december (5), november (5), targets (5), february (5), cisco (5), custom (5), apt28 (5), detects (5), via (5), interface (5), tools (5), user (5), authentication (5), compromised (5), adversary (5), captures (5), version (5), mitre (4), are (4), detection (4), september (4), 2016 (4), responder (4), 2014 (4), actor (4), malware (4), nbtscan (4), magic (4), packets (4), cyber (4), power (4), cloud (4), services (4), libpcap (4), promiscuous (4), environments (4), create (4), poisoning (4), passwords (4), sniffer (4), passively (4), adversaries (4), software (3), cti (3), assets (3), mitigations (3), defenses (3), sub (3), tactics (3), zero (3), day (3), velvet (3), ant (3), secure (3), new (3), 2017 (3), regin (3), server (3), poshc2 (3), penquin (3), messagetap (3), typhoon (3), foggyweb (3), backdoor (3), darkvishnya (3), local (3), get (3), cd00r (3), 2023 (3), security (3), arcanedoor (3), attack (3), ukraine (3), aws (3), virtual (3), web (3), execution (3), cli (3), tcpdump (3), mode (3), with (3), non (3), description (3), ensure (3), this (3), resolution (3), smb (3), protocols (3), information (3), systems (3), requests (3), perform (3), sandworm (3), have (3), http (3), during (3), hosts (3), captured (3), about (3), corporation (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), matrices (2), core (2), objects (2), black (2), lotus (2), labs (2), taking (2), china (2), nexus (2), threat (2), group (2), load (2), shawn (2), marvi (2), operations (2), matt (2), lin (2), austin (2), john (2), wolfram (2), josh (2), murchie (2), lamparski (2), mclellan (2), edge (2), part (2), ivanti (2), connect (2), vpn (2), post (2), exploitation (2), lateral (2), movement (2), targeted (2), attacks (2), state (2), juniper (2), july (2), turla (2), campaign (2), cisa (2), cert (2), talos (2), them (2), uses (2), attacked (2), through (2), direct (2), connection (2), found (2), targeting (2), into (2), how (2), grid (2), industrial (2), configure (2), infrastructure (2), vpc (2), microsoft (2), commands (2), unauthorized (2), followed (2), configuration (2), changes (2), creation (2), sessions (2), azure (2), vtap (2), other (2), instances (2), often (2), suspicious (2), libraries (2), like (2), tshark (2), pcap (2), message (2), strategy (2), platforms (2), analytic (2), users (2), account (2), relay (2), multi (2), factor (2), wired (2), wireless (2), tls (2), filter (2), versamem (2), tool (2), legitimate (2), redirecting (2), control (2), spawnchimera (2), between (2), interfaces (2), salt (2), system (2), been (2), passed (2), based (2), redpenguin (2), module (2), library (2), layers (2), protocol (2), including (2), line (2), dancer (2), sniffpass (2), obtain (2), kimsuky (2), ability (2), defined (2), jumbledpath (2), ports (2), raw (2), socket (2), impacket (2), intercept (2), conduct (2), empire (2), emotet (2), castletap (2), collect (2), apt33 (2), open (2), service (2), electric (2), t1040 (2), using (2), specified (2), details (2), also (2), environment (2), technique (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, crossroads, versa, director, exploitaiton, sygnia, abuses, balancers, persistence, punsaen, boonyakarn, chew, logeswaran, nadarajan, mathew, potaczek, jakub, jozwiak, alex, cloaked, covert, uncovering, larsen, ashley, pearson, lukasz, joseph, pisano, ryan, hall, ron, craft, crew, billy, wong, tyler, cutting, case, studies, daniel, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, cherepanov, rise, telebots, analyzing, disruptive, killdisk, gaffie, kaspersky, lab, global, research, analysis, platform, nation, ownage, gsm, networks, ghost, router, routers, nettitude, python, baumgartner, raiu, leonardo, technical, insight, penquin_x64, sectools, 2003, bezroutchko, man, page, leong, perez, dean, who, reading, your, text, messages, asert, stolen, pencil, academia, fbi, cnmf, https, gov, ncas, alerts, aa20, 301a, weathering, storm, midst, show, where, find, secureauth, ramin, nafisi, nobelium, leads, persistent, schroeder, warner, nelson, github, powershellempire, salvio, banking, theft, golovanov, banks, hartrell, greg, 2002, handle, invisible, fortinet, suspected, chinese, operation, canadian, centre, activity, impacting, asa, vpns, focused, perimeter, response, investigation, elfin, relentless, multiple, organizations, saudi, arabia, brady, indictment, united, states, aleksei, sergeyevich, morenets, smith, read, hospitality, sector, presents, travelers, fireeye, window, russia, charles, hackers, implications, iot, embedded, alert, ta18, 106a, russian, sponsored, actors, luke, paine, looking, glass, spencer, gietzen, abusing, tap, google, overview, amazon, works, references, etc, logging, arista, gear, debug, an0879, redirect, critical, file, session, establishment, an0878, enabling, applescript, triggering, leverages, unified, logs, process, lineage, identify, pfctl, an0877, correlates, abnormal, nic, configurations, root, an0876, monitoring, wireshark, analyzer, driver, loading, indicative, admin, privilege, escalation, nics, an0875, across, det0314, not, granted, permissions, modify, mirrors, unless, explicitly, required, management, m1018, deny, broadcasts, multicast, prevent, segmentation, m1030, wherever, possible, m1032, encrypted, appropriately, best, practices, kerberos, contain, protected, ssl, encrypt, sensitive, m1041, mitigation, hooked, catalina, application, chain, inbound, tomcat, inspecting, parameters, follow, java, modules, dofilter, s1154, velvettap, big, g1047, lookover, tacacs, g1048, monitored, filtered, allowing, pass, while, attacker, controlled, under, s9024, intercepter, g0034, variety, g1045, hashes, after, poisoned, s0174, appears, functionality, smtp, s0019, passive, act, c0056, contains, s0378, look, matching, specific, conditions, s0587, dump, print, whole, content, s0590, listen, parses, starting, ethernet, continues, parsing, sctp, sccp, tcap, finally, extracts, sms, routing, metadata, s0443, exfiltrate, s1186, nirsoft, g0094, remote, jump, s1206, listener, function, extended, berkley, ebpf, designated, s1203, s0357, listeners, incoming, intranet, internet, match, uri, patterns, s0661, target, s0363, observed, hook, apis, s0367, login, g0105, specifc, sequences, s1204, s1224, included, collection, victim, c0046, g0064, deployed, source, netbios, which, usernames, hashed, allowed, close, teams, pineapples, signals, g0007, discover, being, lan, blackenergy, c0028, procedure, examples, live, permalink, last, modified, created, clark, c2defense, eliraz, levi, hunters, itamar, mizrahi, cymptom, oleg, kolesnikov, securonix, tiago, faria, 3coresec, contributors, iaas, linux, windows, macos, discovery, credential, device, still, able, machines, example, gcp, allow, define, send, collected, much, will, cleartext, due, termination, balancer, level, reduce, strain, encrypting, decrypting, then, exfiltration, transfer, order, sniffed, reveal, running, numbers, characteristics, addresses, hostnames, vlan, ids, necessary, subsequent, activities, likely, utilize, aitm, gain, additional, knowledge, middle, stealth, include, especially, those, insecure, unencrypted, websites, proxies, internal, material, refers, place, transit, span, larger, amount, home, join, mclean, hotel, location, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, started, detections,


Text of the page (random words):
network sniffing technique t1040 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise network sniffing network sniffing adversaries may passively sniff network traffic to capture information about an environment including authentication material passed over the network network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection an adversary may place a network interface into promiscuous mode to passively access data in transit over the network or use span ports to capture a larger amount of data data captured via this technique may include user credentials especially those sent over an insecure unencrypted protocol techniques for name service resolution poisoning such as name resolution poisoning and smb relay can also be used to capture credentials to websites proxies and internal systems by redirecting traffic to an adversary network sniffing may reveal configuration details such as running services version numbers and other network characteristics e g ip addresses hostnames vlan ids necessary for subsequent lateral movement and or stealth activities adversaries may likely also utilize network sniffing during adversary in the middle aitm to passively gain additional knowledge about the environment in cloud based environments adversaries may still be able to use traffic mirroring services to sniff network traffic from virtual machines for example aws traffic mirroring gcp packet mirroring and azure vtap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to 1 2 3 often much of this traffic will be in cleartext due to the use of tls termination at the load balancer level to reduce the strain of encrypting and decrypting traffic 4 5 the adversary can then use exfiltration techniques such as transfer data to cloud account in order to access the sniffed traffic 4 on network devices adversaries may perform network captures using network device cli commands such as monitor capture 6 7 id t1040 sub techniques no sub techniques ⓘ tactics credential access discovery ⓘ platforms iaas linux network devices windows macos contributors austin clark c2defense eliraz levi hunters itamar mizrahi cymptom oleg kolesnikov securonix tiago faria 3coresec version 1 7 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description c0028 2015 ukraine electric power attack during the 2015 ukraine electric power attack sandworm team used blackenergy s network sniffer module to discover user credentials being sent over the network between the local lan and the power grid s industrial control systems 8 g0007 apt28 apt28 deployed the open source tool responder to conduct netbios name service poisoning which captured usernames and hashed passwords that allowed access to legitimate credentials 9 10 apt28 close access teams have used wi fi pineapples to intercept wi fi signals and user credentials 11 g0064 apt33 apt33 has used sniffpass to collect credentials by sniffing network traffic 12 c0046 arcanedoor arcanedoor included network packet capture and sniffing for data collection in victim environments 13 14 s1224 castletap castletap has the ability to create a raw promiscuous socket to sniff network traffic 15 s1204 cd00r cd00r can use the libpcap library to monitor captured packets for specifc sequences 16 g0105 darkvishnya darkvishnya used network sniffing to obtain login data 17 s0367 emotet emotet has been observed to hook network apis to monitor network traffic 18 s0363 empire empire can be used to conduct packet captures on target hosts 19 s0661 foggyweb foggyweb can configure custom listeners to passively monitor all incoming http get and post requests sent to the ad fs server from the intranet internet and intercept http requests that match the custom uri patterns defined by the actor 20 s0357 impacket impacket can be used to sniff network traffic via an interface or raw socket 21 s1203 j magic j magic has a pcap listener function that can create an extended berkley packet filter ebpf on designated interfaces and ports 22 s1206 jumbledpath jumbledpath has the ability to perform packet capture on remote devices via actor defined jump hosts 23 g0094 kimsuky kimsuky has used the nirsoft sniffpass network sniffer to obtain passwords sent over non secure protocols 24 25 s1186 line dancer line dancer can create and exfiltrate packet captures from compromised environments 13 s0443 messagetap messagetap uses the libpcap library to listen to all traffic and parses network protocols starting with ethernet and ip layers it continues parsing protocol layers including sctp sccp and tcap and finally extracts sms message data and routing metadata 26 s0590 nbtscan nbtscan can dump and print whole packet content 27 28 s0587 penquin penquin can sniff network traffic to look for packets matching specific conditions 29 30 s0378 poshc2 poshc2 contains a module for taking packet captures on compromised hosts 31 c0056 redpenguin during redpenguin unc3886 used a passive backdoor to act as a libpcap based packet sniffer 32 s0019 regin regin appears to have functionality to sniff for credentials passed over http smtp and smb 33 s0174 responder responder captures hashes and credentials that are sent to the system after the name services have been poisoned 34 g1045 salt typhoon salt typhoon has used a variety of tools and techniques to capture packet data between network interfaces 23 g0034 sandworm team sandworm team has used intercepter ng to sniff passwords in network traffic 35 s9024 spawnchimera spawnchimera has monitored and filtered network traffic on compromised edge devices allowing legitimate traffic to pass while redirecting attacker controlled traffic to infrastructure under adversary control 36 37 g1048 unc3886 unc3886 has used the lookover sniffer to sniff tacacs authentication packets 38 g1047 velvet ant velvet ant has used a custom tool velvettap to perform packet capture from compromised f5 big ip devices 39 s1154 versamem versamem hooked the catalina application filter chain dofilter on compromised systems to monitor all inbound requests to the local tomcat web server inspecting them for parameters like passwords and follow on java modules 40 mitigations id mitigation description m1041 encrypt sensitive information ensure that all wired and or wireless traffic is encrypted appropriately use best practices for authentication protocols such as kerberos and ensure web traffic that may contain credentials is protected by ssl tls m1032 multi factor authentication use multi factor authentication wherever possible m1030 network segmentation deny direct access of broadcasts and multicast sniffing and prevent attacks such as name resolution poisoning and smb relay m1018 user account management in cloud environments ensure that users are not granted permissions to create or modify traffic mirrors unless this is explicitly required detection strategy id name analytic id analytic description det0314 detection strategy for network sniffing across platforms an0875 detects suspicious execution of network monitoring tools e g wireshark tshark microsoft message analyzer driver loading indicative of promiscuous mode or non admin user privilege escalation to access nics for capture an0876 correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump tshark or custom pcap libraries detects abnormal nic configurations and unauthorized sniffing from non root sessions an0877 detects enabling of interface sniffing via packet capture tools or applescript triggering tcpdump leverages unified logs and process lineage to identify suspicious use of pfctl tcpdump or libpcap libraries an0878 detects creation of traffic mirroring sessions e g aws vpc traffic mirroring azure vtap that redirect traffic from critical assets to other virtual instances often followed by file creation or session establishment an0879 detects execution of capture commands via cli monitor capture debug packet etc or unauthorized cli access followed by logging configuration changes on cisco juniper arista gear references amazon web services n d how traffic mirroring works retrieved march 17 2022 google cloud n d packet mirroring overview retrieved march 17 2022 microsoft 2022 february 9 virtual network tap retrieved march 17 2022 spencer gietzen 2019 september 17 abusing vpc traffic mirroring in aws retrieved march 17 2022 luke paine 2020 march 11 through the looking glass part 1 retrieved march 17 2022 us cert 2018 april 20 alert ta18 106a russian state sponsored cyber actors targeting network infrastructure devices retrieved october 19 2020 cisco 2022 august 17 configure and capture embedded packet on software retrieved july 13 2022 charles mclellan 2016 march 4 how hackers attacked ukraine s power grid implications for industrial iot security retrieved september 27 2023 fireeye 2015 apt28 a window into russia s cyber espionage operations retrieved august 19 2015 smith l and read b 2017 august 11 apt28 targets hospitality sector presents threat to travelers retrieved november 17 2024 brady s 2018 october 3 indictment united states vs aleksei sergeyevich morenets et al retrieved october 1 2020 security response attack investigation team 2019 march 27 elfin relentless espionage group targets multiple organizations in saudi arabia and u s retrieved april 10 2019 cisco talos 2024 april 24 arcanedoor new espionage focused campaign found targeting perimeter network devices retrieved january 6 2025 canadian centre for cyber security 2024 april 24 cyber activity impacting cisco asa vpns retrieved january 6 2025 marvi a et al 2023 march 16 fortinet zero day and custom malware used by suspected chinese actor in espionage operation retrieved march 22 2023 hartrell greg 2002 august get a handle on cd00r the invisible backdoor retrieved october 13 2018 golovanov s 2018 december 6 darkvishnya banks attacked through direct connection to local network retrieved may 15 2020 salvio j 2014 june 27 new banking malware uses network sniffing for data theft retrieved march 25 2019 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 ramin nafisi 2021 september 27 foggyweb targeted nobelium malware leads to persistent backdoor retrieved october 4 2021 secureauth n d retrieved january 15 2019 black lotus labs 2025 january 23 the j magic show magic packets and where to find them retrieved february 17 2025 cisco talos 2025 february 20 weathering the storm in the midst of a typhoon retrieved february 24 2025 cisa fbi cnmf 2020 october 27 https us cert cisa gov ncas alerts aa20 301a retrieved november 4 2020 asert team 2018 december 5 stolen pencil campaign targets academia retrieved february 5 2019 leong r perez d dean t 2019 october 31 messagetap who s reading your text messages retrieved may 11 2020 bezroutchko a 2019 november 19 nbtscan man page retrieved march 17 2021 sectools 2003 june 11 nbtscan retrieved march 17 2021 leonardo 2020 may 29 malware technical insight turla penquin_x64 retrieved march 11 2021 baumgartner k and raiu c 2014 december 8 the penquin turla retrieved march 11 2021 nettitude 2018 july 23 python server for poshc2 retrieved april 23 2019 lamparski l et al 2025 march 11 ghost in the router china nexus espionage actor unc3886 targets juniper routers retrieved june 24 2025 kaspersky lab s global research and analysis team 2014 november 24 the regin platform nation state ownage of gsm networks retrieved december 1 2014 gaffie l 2016 august 25 responder retrieved november 17 2017 cherepanov a 2016 december 13 the rise of telebots analyzing disruptive killdisk attacks retrieved june 10 2020 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 matt lin austin larsen john wolfram ashley pearson josh murchie lukasz lamparski joseph pisano ryan hall ron craft shawn crew billy wong tyler mclellan 2024 april 4 cutting edge part 4 ivanti connect secure vpn post exploitation lateral movement case studies retrieved april 16 2026 punsaen boonyakarn shawn chew logeswaran nadarajan mathew potaczek jakub jozwiak and alex marvi 2024 june 18 cloaked and covert uncovering unc3886 espionage operations retrieved september 24 2024 sygnia team 2024 june 3 china nexus threat group velvet ant abuses f5 load balancers for persistence retrieved march 14 2025 black lotus labs 2024 august 27 taking the crossroads the versa director zero day exploitaiton retrieved august 27 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 83 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-83


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1040
X-GitHub-Request-Id CD0A:1459C1:2BC1B9:2C0E2A:6A88B396
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Fri, 21 Aug 2026 20:22:47 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290040-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787343768.674678,VS0,VE105
Vary Accept-Encoding
X-Fastly-Request-ID 56acf87d337f2e4cd36ae89c35b8245115ddfa01
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1040/
access-control-allow-origin *
expires Fri, 21 Aug 2026 20:32:47 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 1F14:16B7D6:2C9E14:2CEA4D:6A88B397
x-github-edge-region fra
accept-ranges bytes
date Fri, 21 Aug 2026 20:22:47 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290022-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787343768.807909,VS0,VE95
vary Accept-Encoding
x-fastly-request-id ad10dc894421966e9736168efcbd8002266d9ae1
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-1761f
expires Fri, 21 Aug 2026 20:32:47 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 0F34:93A43:2AEDFE:2B39CF:6A88B397
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 20:22:48 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290022-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787343768.911527,VS0,VE128
vary Accept-Encoding
x-fastly-request-id 52ddb016ee2a48d2eead96b2ea0f89f54aa403eb
content-length 17780

Meta Tags

title="Network Sniffing, Technique T1040 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size17780
load time (s)0.648357
redirect count2
speed download27438
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"