Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0296 — Detect Adversary-in-the-Middle via Network and Configuration Anomalies
DET0296

Detect Adversary-in-the-Middle via Network and Configuration Anomalies

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0823 Analytic 0823
Windows

Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=3, 22
[MonitoredRegistryPaths] Specific network stack and DNS registry keys that vary by enterprise configuration.
[DowngradeCipherList] List of weak/legacy ciphers tuned per environment for TLS downgrade detection.
[TimeWindow] Correlation period between config changes and abnormal network connections.
AN0824 Analytic 0824
Linux

Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.

auditd:SYSCALL open, write NSM:Flow Unexpected ARP replies or DNS responses inconsistent with authoritative servers
[MonitoredFiles] List of system files shaping traffic flow (hosts, resolv.conf, PAM modules).
[ARPThreshold] Rate/volume thresholds for ARP/DNS anomalies tuned per subnet.
AN0825 Analytic 0825
macOS

Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.

macos:unifiedlog Configuration profile modified or new profile installed NSM:Flow TLS downgrade or inconsistent DNS answers
[ProfileIdentifiers] Known good vs suspicious configuration profiles per enterprise baseline.
[TLSVersionThreshold] Minimum TLS version accepted in network traffic inspection.
AN0826 Analytic 0826
Network Devices

Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.

NSM:Flow Unexpected route changes or duplicate gateway advertisements networkdevice:config Configuration file modified or replaced on network device
[RoutingPolicyBaseline] Expected routing and BGP/OSPF paths for validation.
[FirmwareChecksum] Baseline image checksum per device type used to detect tampering.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0296
STIX ID
x-mitre-detection-strategy--0eb48c77-9056-4178-900b-7ac23fd1c7cd
Analytics
4
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.