Adversary-in-the-Middle: ARP Cache Poisoning T1557.002

Tactics: Credential Access, Collection

Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices. This activity may be used to enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation.

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
facility3eq 3pm, port_security, sisf
mnemonic3eq 2, in 1err_disable, ip_theft, mac_and_ip_theft, mac_theft, psecure_violation
disable_cause2eq 2arp-inspection, psecure-violation

Top indicator values (12 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
facilityeq
pm
22
facilityeq
port_security
1
facilityeq
sisf
1
mnemoniceq
err_disable
22
mnemoniceq
psecure_violation
1
mnemoniceq
psecure_violation_vlan
1
disable_causeeq
arp-inspection
1
disable_causeeq
psecure-violation
1
mnemonicin
ip_theft
1
mnemonicin
mac_and_ip_theft
1
mnemonicin
mac_theft
1
mnemonicin
pak_drop
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Network

Domain: Network

Splunk 3 rules