Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0536 — Detection Strategy for Wi-Fi Networks
DET0536

Detection Strategy for Wi-Fi Networks

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1476 Analytic 1476
Windows

Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.

WinEventLog:Microsoft-Windows-WLAN-AutoConfig EventCode=8001, 8002, 8003 WinEventLog:Security EventCode=4776, 4625
[KnownSSIDList] Defines approved Wi-Fi SSIDs for the environment; deviations may indicate malicious connection attempts.
[GeoLocationContext] Correlates expected physical location of systems with observed Wi-Fi connections to detect anomalies.
AN1477 Analytic 1477
Linux

Detects unauthorized wireless associations by monitoring wpa_supplicant logs, NetworkManager events, and system calls related to interface state changes. Anomalies include repeated association failures, new SSIDs outside baselined values, and rogue AP connections.

linux:syslog New Wi-Fi connection established or repeated association failures auditd:SYSCALL ioctl: Changes to wireless network interfaces (up, down, reassociate)
[AllowedSSIDRegex] Regex-based whitelist of corporate SSIDs; anomalous matches indicate suspicious activity.
[RetryThreshold] Number of failed association attempts allowed before triggering detection.
AN1478 Analytic 1478
macOS

Detects unauthorized Wi-Fi associations and SSID scanning activity using unified logs and airport command telemetry. Anomalies include rapid SSID switching, connections to unapproved SSIDs, or repeated authentication failures.

macos:unifiedlog Association and authentication events including failures and new SSIDs macos:osquery query: Historical list of associated SSIDs compared against baseline
[BaselineSSIDHistory] Historical record of corporate SSID associations per device; deviations may indicate rogue AP usage.
AN1479 Analytic 1479
Network Devices

Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points.

NSM:Firewall rule_modification: New or modified firewall rules related to wireless interfaces WIDS:AssociationLogs Unauthorized AP or anomalous MAC address connection attempts
[AuthorizedAPList] Defines known access points and MAC addresses; deviations highlight rogue or unauthorized devices.

Detected Techniques

1

Initial Access (1)

Details

MITRE ID
DET0536
STIX ID
x-mitre-detection-strategy--f9c29db2-8790-4255-957f-9a02f1d8d024
Analytics
4
Techniques Detected
1
By Tactic
Initial Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.