Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1557

T1557Adversary-in-the-Middle

T1557 — Adversary-in-the-Middle is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 11 detection use cases covering it and 6 threat-intel articles citing it.

Credential AccessCollection
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
6Articles
4Sub-techniques
2Tactics

Sub-techniques (4)

Use cases covering this technique (11)

Cisco ASA - Packet Capture Activity ESCU actions · hunting P Detect Rogue DHCP Server ESCU actions · alerting P [LLM] Node.js process direct DNS egress to external resolver (vm2 dns.setServers host hijack) Bespoke c2 · hunting DSΣPDDCS [LLM] Browser navigation to BitB Calendly-lookalike phishing host (rare .cfd/.work TLD) Bespoke exploit · hunting DSΣPDDCS [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN Bespoke actions · hunting DSPDD [LLM] JWR real-time exfil & operator WebSocket channel (the_final_interface / addCvv / webSocket/QT) Bespoke c2 · alerting DSΣP [LLM] First-seen browser egress to abused cloud-PaaS phishing domains (workers.dev / pages.dev / vercel.app / github.io / netlify.app / dweb.link) Bespoke delivery · hunting DSPDDCS [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP Bespoke actions · alerting DS [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Vulnerable Maven (<3.8.1) invocation revealed by build classpath — CVE-2021-26291 Bespoke exploit · hunting DSPDDCS [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291 Bespoke delivery · hunting DSPDDCS

Articles citing this technique (6)