| T1557.002 — ARP Cache Poisoning |
technique |
technique/T1557.002 |
Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked de |
| Address Resolution Protocol (ARP) |
protocol |
protocol/arp |
ARP resolves an IPv4 address to a link-layer (MAC) address on a local network segment. Hosts cache answers in an ARP table. There is no cryp |
| D3-NTF — Network Traffic Filtering |
defense |
defense/D3-NTF |
Restricting network traffic originating from any location. |
| D3-APCA — Application Protocol Command Analysis |
defense |
defense/D3-APCA |
Analyzing application protocol level remote commands to detect unauthorized activity. |
| D3-CSPP — Client-server Payload Profiling |
defense |
defense/D3-CSPP |
Comparing client-server request and response payloads to a baseline profile to identify outliers. |
| D3-NTCD — Network Traffic Community Deviation |
defense |
defense/D3-NTCD |
Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication. |
| D3-NTSA — Network Traffic Signature Analysis |
defense |
defense/D3-NTSA |
Analyzing network traffic and compares it to known signatures |
| D3-PMAD — Protocol Metadata Anomaly Detection |
defense |
defense/D3-PMAD |
Collecting network communication protocol metadata and identifying statistical outliers. |
| D3-RTSD — Remote Terminal Session Detection |
defense |
defense/D3-RTSD |
Detection of an unauthorized remote live terminal console session by examining network traffic to a network host. |
| D3-UGLPA — User Geolocation Logon Pattern Analysis |
defense |
defense/D3-UGLPA |
Monitoring geolocation data of user logon attempts and comparing it to a baseline user behavior profile to identify anomalies in logon locat |
| D3-PHDURA — Per Host Download-Upload Ratio Analysis |
defense |
defense/D3-PHDURA |
Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host. |
| CAPEC-141 — Cache Poisoning |
attack-pattern |
attack-pattern/CAPEC-141 |
An attacker exploits the functionality of cache technologies to cause specific data to be cached that aids the attackers' objectives. This d |
| ARP cache poisoning |
concept |
concept/arp-cache-poisoning |
ARP cache poisoning (ARP spoofing) is an adversary-in-the-middle technique where an attacker sends forged ARP replies so victims associate t |