kevmap

TechniquesT1557 › AN0825

AN0825 Analytic 0825

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.</p>
Detects
T1557 Adversary-in-the-Middle
Part of
DET0296 Detect Adversary-in-the-Middle via Network and Configuration Anomalies

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogConfiguration profile modified or new profile installedDC0038 Application Log Content
NSM:FlowTLS downgrade or inconsistent DNS answersDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ProfileIdentifiersKnown good vs suspicious configuration profiles per enterprise baseline.
TLSVersionThresholdMinimum TLS version accepted in network traffic inspection.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-5591Fortinet FortiOSMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale