Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1040

T1040Network Sniffing

T1040 — Network Sniffing is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 5 detection use cases covering it and 1 threat-intel article citing it.

Credential AccessDiscovery
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (5)

Cisco ASA - Packet Capture Activity ESCU actions · hunting P Windows Network Sniffing Tool Executed ESCU actions · hunting P Cisco SNMP Community String Configuration Changes ESCU actions · hunting P Splunk Identified SSL TLS Certificates ESCU actions · hunting P [LLM] Evooo1Bot credential sniffer artifact (/tmp/.sniff.log capture file) Bespoke actions · alerting DSΣPCS

Articles citing this technique (1)