FORENSIA

ATT&CK · T1040

Network Sniffing

Tactics: credential-access, discovery

About

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data. Data captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol. Techniques for name service resolution poisoning, such as Name Resolution Poisoning and SMB Relay, can also be used to capture credentials to websites, proxies, and internal systems by redirecting traffic to an adversary. Network sniffing may reveal configuration details, such as running services, version numbers, and other network characteristics (e.g. IP addresses, hostnames, VLAN IDs) necessary for subsequent Lateral Movement and/or Stealth activities. Adversaries may likely also utilize network sniffing during Adversary-in-the-Middle (AiTM) to passively gain additional knowledge about the environment. In cloud-based environments, adversaries may still be able to use traffic mirroring services to sniff network traffic from virtual machines. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to. Often, much of this traffic will be in cleartext due to the use of TLS termination at the load balancer level to reduce the strain of encrypting and decrypting traffic. The adversary can then use exfiltration techniques such as Transfer Data to Cloud Account in order to access the sniffed traffic. On network devices, adversaries may perform network captures using Network Device CLI commands such as `monitor capture`.

Platforms: IaaS, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

8 known groups

Software

17 malware/tools implement this

ReginResponderImpacketEmpireEmotetPoshC2MESSAGETAPPenquinNBTscanFoggyWebVersaMemLine DancerJ-magiccd00rJumbledPathCASTLETAPSPAWNCHIMERA

Corpus indicators tagged with this technique

49 indicators in the corpus carry T1040.

IndicatorTypeFamilySevSrc
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33dbsha256ransomware802
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9dfsha256ransomware804
f8965fdce668692c3785afa3559159f9a18287bc0d53abb21902895a8ecf221bsha256ransomware802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
9ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1esha256ransomware802
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
ab5ad04bb822435e5453706cd86cc001ee555aeesha1ransomware782
6afc6b04cf73dd461e4a4956365f25c1f1162387sha1ransomware782
268a8420b791df46380ed9ad69905207e15d8a7csha1phishing781
96f0dbf52aed0afd43e44500116b04b674f7358esha1ransomware782
7556ae58c215b8245a43f764f0676c7a8f0fdd1asha1ransomware782
1fa071303fb846308571e64727501fb98b1c2be6sha1ransomware782
e7cc7b32d844ec6a2f41f0efbc64a0783afb56e4sha1ransomware782
68fec379f2ae76c3d2ce913f7be650cea1d06990sha1ransomware784
d2f72897e8986303d5567eb2384932b8md5ransomware76106
de1522f9219497632f30f8a6e72f26b6md5ransomware76106
7f74bb6ba185978134c318bc5f91d23cmd5phishing761
d12a5b36dd00586cc374a1cae43efed4md5ransomware76106
846dc77c1246db20d976346e0e359502md5ransomware76110
02944c8a5535cdb5b2cbb893db2d5acfmd5ransomware76110
5761bd63da03686fc480245da7bd1e9fmd5ransomware764
fdae2beb813778b4540a997706862096md5ransomware76106
9321a61a25c7961d9f36852ecaa86f55md5ransomware762
b6b51508ad6f462c45fe102c85d246c8md5ransomware762

Showing the top 30 by severity of 49.