T1557 Adversary-in-the-Middle
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or replay attacks ([Exploitation for Credential…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential SMB Relay Attack Tool Executioncriticaltest · windows
- HackTool - ADCSPwn Executionhightest · windows
- HackTool - Impacket Tools Executionhightest · windows
- Local Privilege Escalation Indicator TabTiphightest · windows
- RottenPotato Like Attack Patternhightest · windows
- WinDivert Driver Loadhightest · windows
- Attempts of Kerberos Coercion Via DNS SPN Spoofinghighexperimental · windows
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulationhighexperimental · windows
- Suspicious Child Process of Notepad++ Updater - GUP.Exehighexperimental · windows
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofinghighexperimental · windows
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Networkhighexperimental · zeek
- Uncommon File Created by Notepad++ Updater Gup.EXEhighexperimental · windows
- Potential PetitPotam Attack Via EFS RPC Callsmediumtest · zeek
- Potential Suspicious Activity Using SeCEditmediumtest · windows
- ISATAP Router Address Was Setmediumexperimental · windows
- Notepad++ Updater DNS Query to Uncommon Domainsmedium # can be upgraded to high after tuning with known legitimate dns queriesexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.