// MITRE ATT&CK
T1557 · Adversary-in-the-Middle
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techni...
How to detect & mitigate it
Detecting Adversary-in-the-Middle starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (4)
T1557.001
Name Resolution Poisoning and SMB Relay T1557.002
ARP Cache Poisoning T1557.003
DHCP Spoofing T1557.004
Evil Twin
Name Resolution Poisoning and SMB Relay T1557.002
ARP Cache Poisoning T1557.003
DHCP Spoofing T1557.004
Evil Twin
Related techniques
T1110.001
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.