Umbra Wiki concept concept/adversary-in-the-middle
Back to wiki

Adversary-in-the-middle (AitM)

provenance: curated · ATT&CK: T1557

Adversary-in-the-middle

AitM (historically MITM) techniques position an attacker between parties to intercept or alter communications. On local networks this often includes ARP cache poisoning; on higher layers it includes rogue proxies, evil twin Wi‑Fi, and some phishing kit patterns.

Always scope investigations to authorized networks and assets.