Network Sniffing T0842

ICS Tactic: Discovery

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
AlertName4in 2, contains 1, eq 1ARP Spoofing, Abnormal Traffic Bandwidth, Abnormal Traffic Bandwidth Between Devices, Abnormal usage of MAC Addresses, Device Failed to Receive a Dynamic IP Address
ProviderName4eq 4IoTSecurity
isNew4eq 4True

Top indicator values (12 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
ProviderNameeq
IoTSecurity
415
isNeweq
True
415
AlertNamecontains
scan
1
AlertNameeq
Device Failed to Receive a Dynamic IP Address
1
AlertNamein
ARP Spoofing
1
AlertNamein
Abnormal Traffic Bandwidth
1
AlertNamein
Abnormal Traffic Bandwidth Between Devices
1
AlertNamein
Abnormal usage of MAC Addresses
1
AlertNamein
Field Device Discovered Unexpectedly
1
AlertNamein
ICMP Flooding
1
AlertNamein
New Asset Detected
1
AlertNamein
New LLDP Device Configuration
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Cross-platform

Domain: Endpoint

Kusto 4 rules