T1557Adversary-in-the-Middle
T1557 — Adversary-in-the-Middle is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 11 detection use cases covering it and 6 threat-intel articles citing it.
Credential AccessCollection
11Use cases
6Articles
4Sub-techniques
2Tactics
Sub-techniques (4)
Use cases covering this technique (11)
Cisco ASA - Packet Capture Activity Detect Rogue DHCP Server [LLM] Node.js process direct DNS egress to external resolver (vm2 dns.setServers host hijack) [LLM] Browser navigation to BitB Calendly-lookalike phishing host (rare .cfd/.work TLD) [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN [LLM] JWR real-time exfil & operator WebSocket channel (the_final_interface / addCvv / webSocket/QT) [LLM] First-seen browser egress to abused cloud-PaaS phishing domains (workers.dev / pages.dev / vercel.app / github.io / netlify.app / dweb.link) [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure [LLM] Vulnerable Maven (<3.8.1) invocation revealed by build classpath — CVE-2021-26291 [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291Articles citing this technique (6)
high Curiouser and Curiouser art-52