| Adversary-in-the-middle (AitM) |
concept |
concept/adversary-in-the-middle |
**AitM** (historically MITM) techniques position an attacker between parties to intercept or alter communications. On local networks this of |
| ARP cache poisoning |
concept |
concept/arp-cache-poisoning |
**ARP cache poisoning** (ARP spoofing) is an adversary-in-the-middle technique where an attacker sends forged ARP replies so victims associa |
| Address Resolution Protocol (ARP) |
protocol |
protocol/arp |
ARP resolves an **IPv4 address** to a **link-layer (MAC) address** on a local network segment. Hosts cache answers in an ARP table. There is |
| T1557.002 — ARP Cache Poisoning |
technique |
technique/T1557.002 |
Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked de |