Meta tags:
Headings (most frequently used words):
adversary, in, the, middle, procedure, examples, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
the (38), and (29), retrieved (24), network (23), traffic (18), that (16), may (15), 2026 (12), all (12), middle (11), att (10), dns (10), #adversary (10), t1557 (10), with (9), can (9), aitm (9), victim (9), adversaries (8), october (8), 2021 (8), access (8), for (8), enterprise (7), techniques (7), downgrade (7), data (6), july (6), user (6), tls (6), used (6), such (6), ics (5), mobile (5), none (5), sea (5), turtle (5), service (5), web (5), 2020 (5), credentials (5), evilginx (5), january (5), attacks (5), protocols (5), configuration (5), arp (5), version (5), position (5), mitre (4), use (4), resources (4), detection (4), defenses (4), tactics (4), 2019 (4), new (4), november (4), 2024 (4), 2022 (4), august (4), 2025 (4), june (4), from (4), token (4), tokens (4), malware (4), devices (4), december (4), detects (4), unauthorized (4), changes (4), certificate (4), activity (4), name (4), not (4), information (4), legitimate (4), between (4), are (3), website (3), software (3), cti (3), components (3), analytics (3), mitigations (3), sub (3), core (3), cisco (3), april (3), nppspy (3), https (3), kali365 (3), phishing (3), march (3), gretzky (3), 2023 (3), 2017 (3), arcanedoor (3), protocol (3), application (3), users (3), ssl (3), system (3), etc (3), suspicious (3), poisoning (3), authentication (3), description (3), attempt (3), intercept (3), host (3), infrastructure (3), modified (3), credential (3), malicious (3), http (3), has (3), steal (3), transmitted (3), session (3), also (3), corporation (2), cookie (2), domains (2), reference (2), campaigns (2), groups (2), strategies (2), assets (2), matrices (2), objects (2), swimming (2), hijacking (2), talos (2), trust (2), passwords (2), patrick (2), espionage (2), campaign (2), september (2), cisa (2), fbi (2), microsoft (2), artic (2), wolf (2), labs (2), your (2), 2018 (2), found (2), team (2), february (2), using (2), man (2), attack (2), how (2), prevent (2), detect (2), threat (2), day (2), exploitation (2), included (2), through (2), spoofing (2), file (2), edits (2), unexpected (2), abnormal (2), patterns (2), indicative (2), interception (2), correlates (2), modifications (2), subsequent (2), sessions (2), analytic (2), about (2), errors (2), their (2), segmentation (2), mitigate (2), intrusion (2), prevention (2), identify (2), limit (2), conditions (2), within (2), environment (2), legacy (2), leveraged (2), ensure (2), disable (2), controlled (2), enable (2), capture (2), process (2), winlogon (2), windows (2), redirecting (2), payload (2), mustang (2), panda (2), intercepts (2), parameter (2), line (2), runner (2), kimsuky (2), created (2), act (2), relay (2), including (2), cookies (2), evilginx2 (2), potentially (2), monitor (2), dok (2), device (2), yugoslavskiy (2), 004 (2), 003 (2), 002 (2), 001 (2), leverage (2), support (2), manipulation (2), manipulate (2), additional (2), more (2), technique (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, preferences, changelog, privacy, policy, terms, contact, reset, filters, paul, rascagneres, keeps, finds, victims, abuses, internet, dray, agha, cleartext, shenanigans, gifting, whitsell, deception, depth, prc, nexus, hijacks, target, diplomats, cnmf, cert, gov, ncas, alerts, aa20, 301a, trevor, hilligoss, anatomy, 365, kit, telegram, hype, takedown, theater, bingo, don, let, code, winner, everts, stealing, phishes, mastery, next, generation, 2fa, ofer, caspi, osx, catching, wants, read, wardle, mac, focused, targeting, perimeter, cinnamon, alashwali, rasmussen, what, taxonomy, praetorian, editorial, 2014, incident, response, respond, cloud, theft, adair, lancaster, volexity, research, driftingcloud, zero, sophos, firewall, insidious, breach, kuzmenko, blocker, miner, abendan, 2012, changer, trojans, direct, threats, ttint, iot, remote, trojan, spread, vulnerabilities, rapid7, mitm, references, firmware, enabling, positioning, route, injection, behavioral, focus, sudden, routing, tables, image, integrity, failures, an0826, profiles, an0825, hosts, resolv, conf, broadcasts, creation, an0824, attempts, registry, unusual, flows, events, an0823, via, anomalies, det0296, strategy, train, own, certificates, arise, when, does, match, one, expected, training, m1017, isolate, require, broad, this, least, alleviate, scope, m1030, systems, level, m1031, reshape, otherwise, produce, resource, over, m1035, appliances, based, security, block, necessary, filter, m1037, wired, wireless, encrypted, appropriately, best, practices, kerberos, contain, protected, encrypt, sensitive, m1041, applicable, especially, those, needed, remove, feature, program, m1042, mitigation, records, providers, redirect, servers, g1041, opens, listener, typically, contacted, alternative, rpc, channel, set, dll, recording, plaintext, entered, into, effectively, intercepting, logon, mpnotify, exe, s1131, captive, portal, hijack, redirected, webpage, prompted, download, g0129, requests, asa, looking, request, character, dependent, matches, value, contained, then, written, lua, script, executed, s1188, versions, phproxy, examine, accessed, g0094, obfuscated, landing, pages, communications, services, s9044, ability, phished, usernames, s9003, proxies, alter, s0281, parse, command, control, sent, c0046, procedure, examples, live, permalink, last, daniil, atomic, coverage, project, mayuresh, dani, qualys, nec, contributors, linux, macos, platforms, collection, modify, setup, similar, flowing, appropriate, destination, impair, denial, example, settings, other, activities, preventing, accessing, sites, pushing, order, establish, negotiating, less, secure, deprecated, weaker, communication, encryption, algorithm, themselves, two, networked, follow, behaviors, replay, abusing, features, common, networking, determine, flow, llmnr, force, communicate, they, collect, perform, actions, sniffing, evil, twin, dhcp, cache, resolution, smb, home, open, join, mclean, hotel, location, details, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, get, started, detections,
Text of the page (random words):
adversary in the middle technique t1557 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise adversary in the middle adversary in the middle sub techniques 4 id name t1557 001 name resolution poisoning and smb relay t1557 002 arp cache poisoning t1557 003 dhcp spoofing t1557 004 evil twin adversaries may attempt to position themselves between two or more networked devices using an adversary in the middle aitm technique to support follow on behaviors such as network sniffing transmitted data manipulation or replay attacks exploitation for credential access by abusing features of common networking protocols that can determine the flow of network traffic e g arp dns llmnr etc adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions 1 for example adversaries may manipulate victim dns settings to enable other malicious activities such as preventing redirecting users from accessing legitimate sites and or pushing additional malware 2 3 4 adversaries may also manipulate dns and leverage their position in order to intercept user credentials including access tokens steal application access token and session cookies steal web session cookie 5 6 downgrade attack s can also be used to establish an aitm position such as by negotiating a less secure deprecated or weaker version of communication protocol ssl tls or encryption algorithm 7 8 9 adversaries may also leverage the aitm position to attempt to monitor and or modify traffic such as in transmitted data manipulation adversaries can setup a position similar to aitm to prevent traffic from flowing to the appropriate destination potentially to impair defenses and or in support of a network denial of service id t1557 sub techniques t1557 001 t1557 002 t1557 003 t1557 004 ⓘ tactics credential access collection ⓘ platforms linux network devices windows macos contributors daniil yugoslavskiy yugoslavskiy atomic threat coverage project mayuresh dani qualys nec version 2 5 created 11 february 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0046 arcanedoor arcanedoor included interception of http traffic to victim devices to identify and parse command and control information sent to the device 10 s0281 dok dok proxies web traffic to potentially monitor and alter victim http s traffic 11 12 s9003 evilginx2 evilginx2 has the ability to act as an adversary in the middle aitm relay between a legitimate website and a phished user to capture all transmitted data including usernames passwords authentication tokens and session cookies and tokens 13 14 15 16 s9044 kali365 kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions 17 18 19 g0094 kimsuky kimsuky has used modified versions of phproxy to examine web traffic between the victim and the accessed website 20 s1188 line runner line runner intercepts http requests to the victim cisco asa looking for a request with a 32 character victim dependent parameter if that parameter matches a value in the malware a contained payload is then written to a lua script and executed 10 g0129 mustang panda mustang panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload 21 s1131 nppspy nppspy opens a new network listener for the mpnotify exe process that is typically contacted by the winlogon process in windows a new alternative rpc channel is set up with a malicious dll recording plaintext credentials entered into winlogon effectively intercepting and redirecting the logon information 22 g1041 sea turtle sea turtle modified dns records at service providers to redirect traffic from legitimate resources to sea turtle controlled servers to enable adversary in the middle attacks for credential capture 23 24 mitigations id mitigation description m1042 disable or remove feature or program disable legacy network protocols that may be used to intercept network traffic if applicable especially those that are not needed within an environment m1041 encrypt sensitive information ensure that all wired and or wireless traffic is encrypted appropriately use best practices for authentication protocols such as kerberos and ensure web traffic that may contain credentials is protected by ssl tls m1037 filter network traffic use network appliances and host based security software to block network traffic that is not necessary within the environment such as legacy protocols that may be leveraged for aitm conditions m1035 limit access to resource over network limit access to network infrastructure and resources that can be used to reshape traffic or otherwise produce aitm conditions m1031 network intrusion prevention network intrusion detection and prevention systems that can identify traffic patterns indicative of aitm activity can be used to mitigate activity at the network level m1030 network segmentation network segmentation can be used to isolate infrastructure components that do not require broad network access this may mitigate or at least alleviate the scope of aitm activity m1017 user training train users to be suspicious about certificate errors adversaries may use their own certificates in an attempt to intercept https traffic certificate errors may arise when the application s certificate does not match the one expected by the host detection strategy id name analytic id analytic description det0296 detect adversary in the middle via network and configuration anomalies an0823 detects suspicious dns arp poisoning attempts unauthorized modifications to registry network configuration or abnormal tls downgrade activity correlates changes in system configuration with subsequent unusual network flows or authentication events an0824 detects unauthorized edits to etc hosts etc resolv conf or suspicious arp broadcasts correlates file modifications with subsequent unexpected network sessions or service creation an0825 detects unauthorized edits to system configuration profiles unexpected certificate trust changes or abnormal arp dns patterns indicative of interception an0826 detects unauthorized firmware or configuration changes enabling adversary in the middle positioning e g route injection dns spoofing ssl downgrade behavioral analytics focus on sudden changes to routing tables or image file integrity failures references rapid7 n d man in the middle mitm attacks retrieved march 2 2020 tu l ma y ye g 2020 october 1 ttint an iot remote access trojan spread through 2 0 day vulnerabilities retrieved october 28 2021 abendan o 2012 june 14 how dns changer trojans direct users to threats retrieved october 28 2021 kuzmenko a 2021 march 10 ad blocker with miner included retrieved october 28 2021 adair s lancaster t volexity threat research 2022 june 15 driftingcloud zero day sophos firewall exploitation and an insidious breach retrieved july 1 2022 microsoft incident response 2022 november 16 token tactics how to prevent detect and respond to cloud token theft retrieved december 26 2023 praetorian editorial team 2014 august 19 man in the middle tls protocol downgrade attack retrieved december 8 2021 alashwali e s rasmussen k 2019 january 26 what s in a downgrade a taxonomy of downgrade attacks in the tls protocol and application protocols using tls retrieved december 7 2021 team cinnamon 2017 february 3 downgrade attacks retrieved december 9 2021 cisco talos 2024 april 24 arcanedoor new espionage focused campaign found targeting perimeter network devices retrieved january 6 2025 patrick wardle n d mac malware of 2017 retrieved september 21 2018 ofer caspi 2017 may 4 osx malware is catching up and it wants to read your https traffic retrieved october 5 2021 gretzky k 2018 july 26 evilginx 2 next generation of phishing 2fa tokens retrieved october 14 2019 gretzky k 2023 may 10 evilginx 3 0 evilginx mastery retrieved january 27 2026 gretzky k 2023 august 24 evilginx 3 2 swimming with the phishes retrieved january 27 2026 everts m 2025 march 28 stealing user credentials with evilginx retrieved january 27 2026 artic wolf labs 2026 april 24 token bingo don t let your code be the winner retrieved july 30 2026 artic wolf labs 2026 june 2 retrieved july 30 2026 trevor hilligoss 2026 june 11 kali365 anatomy of a microsoft 365 phishing as a service kit from telegram hype to fbi takedown theater retrieved july 30 2026 cisa fbi cnmf 2020 october 27 https us cert cisa gov ncas alerts aa20 301a retrieved november 4 2020 patrick whitsell 2025 august 25 deception in depth prc nexus espionage campaign hijacks web traffic to target diplomats retrieved september 9 2025 dray agha 2022 august 16 cleartext shenanigans gifting user passwords to adversaries with nppspy retrieved may 17 2024 cisco talos 2019 april 17 sea turtle dns hijacking abuses trust in core internet service retrieved november 20 2024 paul rascagneres 2019 july 9 sea turtle keeps on swimming finds new victims dns hijacking techniques retrieved november 20 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|