Adversary-in-the-middle (AitM)
Adversary-in-the-middle
AitM (historically MITM) techniques position an attacker between parties to intercept or alter communications. On local networks this often includes ARP cache poisoning; on higher layers it includes rogue proxies, evil twin Wi‑Fi, and some phishing kit patterns.
Always scope investigations to authorized networks and assets.