Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1557

T1557Adversary-in-the-Middle

T1557 — Adversary-in-the-Middle is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 6 detection use cases covering it and 3 threat-intel articles citing it.

Credential AccessCollection
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
3Articles
4Sub-techniques
2Tactics

Sub-techniques (4)

Use cases covering this technique (6)

Cisco ASA - Packet Capture Activity ESCU actions · hunting P Detect Rogue DHCP Server ESCU actions · alerting P [LLM] Endpoint traffic to cubepilot.org during 24 Jul 2026 DNS-hijack / AiTM window Bespoke delivery · hunting DSPDDCS [LLM] AD CS CA server initiates SMB(445)+LDAP(389) to a non-DC host (Certighost chase relay) Bespoke exploit · hunting DSPCS [LLM] Vulnerable Maven (<3.8.1) invocation revealed by build classpath — CVE-2021-26291 Bespoke exploit · hunting DSPDDCS [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291 Bespoke delivery · hunting DSPDDCS

Articles citing this technique (3)