kevmap

TechniquesT1557 › AN0823

AN0823 Analytic 0823

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.</p>
Detects
T1557 Adversary-in-the-Middle
Part of
DET0296 Detect Adversary-in-the-Middle via Network and Configuration Anomalies

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4663, 4670, 4656DC0063 Windows Registry Key Modification
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MonitoredRegistryPathsSpecific network stack and DNS registry keys that vary by enterprise configuration.
DowngradeCipherListList of weak/legacy ciphers tuned per environment for TLS downgrade detection.
TimeWindowCorrelation period between config changes and abnormal network connections.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-5591Fortinet FortiOSMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale