Adversary-in-the-Middle T1557

Tactics: Credential Access, Collection

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Events covered

23 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 69 rules share fields, values, and exclusions.

Fields filtered most (127 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
host.os.type13eq 13
EventID12eq 11, in 35137, 4624, 5145, 4625, 4662
src_ip10is_not_null 5, ne 4, eq 2, in 2, cidr_match 1::1, 127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
EventType8eq 7, in 1login_success, associatevpcwithhostedzone, authorize, device_register_unregister_event, exec
data_stream.dataset8eq 7, in 1google_workspace.login, aws.cloudtrail, azure.auditlogs, azure.platformlogs, azure.signinlogs
CommandLine7contains 7, ends_with 1, match 1 --adcs , --port , /ntlm:ntlmhash , ntlmrelay, smbrelay
LogonType7eq 7Network
Image6ends_with 5, contains 2\gup.exe, \atexec_windows.exe, \cmd.exe, \cscript.exe, \dcomexec_windows.exe
AuthenticationPackageName5eq 5kerberos, ntlm, NTLM
ObjectDN5contains 2, starts_with 2, wildcard 1*UWhRC*BAAAA*MicrosoftDNS*, 1uwhrca, DC=*,, DC=wpad,, aaaaa
ObjectClass4eq 4dnsnode, dnsNode
Provider_Name4eq 4login, microsoft-windows-distributedcom, microsoft-windows-iphlpsvc, route53.amazonaws.com
QueryName4contains 2, ends_with 1, eq 1, wildcard 1*uwhrc*baaaa*, .azurewebsites.net, .githubusercontent.com, .googleapis.com, 1uwhrc
event.outcome4eq 4success
event.type4eq 3, in 1change, start, process_started

Top indicator values (465 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
LogonTypeeq
Network
741
EventIDeq
5137
614
EventIDeq
5145
423
EventIDeq
4662
215
EventIDeq
5136
245
event.outcomeeq
success
4369
src_ipne
127.0.0.1
423
src_ipne
::1
421
userends_with
$
45
EventIDin
4624
37
EventIDin
4625
37
ObjectClasseq
dnsnode
33
AppDisplayNameeq
Azure Portal
22
AuthenticationPackageNameeq
kerberos
25
AuthenticationPackageNameeq
ntlm
27
Esql.distance_kmge
500
22
Esql.region_countge
2
22
Esql.region_countle
5
22
Esql.travel_kmhge
800
22
Imagecontains
\ntlmrelayx
22
Imagecontains
\smbrelayx
22
Imageends_with
\gup.exe
25
computer_namestarts_with
substring(user.name, 0, (-1))
22
event.typeeq
change
294
facilityeq
pm
22
file.nameeq
dhcpserver
22
file.nameeq
dnsserver
22
file.nameeq
efsrpc
23
file.nameeq
eventlog
22
file.nameeq
fssagentrpc
23

Exclusions (96 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipends_with
host.ip
4
computer_namestarts_with
substring(user.name, 0, (-1))
2
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
Imagecontains
hotpotatoes
1
Imagecontains
hotpotatoes6
1
Imagecontains
hotpotatoes7
1
Imagewildcard
?:\program files (x86)\*.exe
1
Imagewildcard
?:\program files\*.exe
1
Imagewildcard
?:\programdata\bomgar-*\*\bomgar-scc.exe
1
Imagewildcard
?:\programdata\bomgar-*\*\sra-pin.exe
1
Imagewildcard
?:\programdata\ctes\components\sng\abtsngsvc.exe
1
Imagewildcard
?:\programdata\ctes\components\svc\cteshostsvc.exe
1
Imagewildcard
?:\programdata\ctes\ctes.exe
1
Imagewildcard
?:\programdata\lenovo\vantage\addins\lenovohardwarescanaddin\*\ldeapi.server.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 23 rules

Elastic 26 rules

Splunk 11 rules

Kusto 9 rules