kevmap

TechniquesT1557 › AN0826

AN0826 Analytic 0826

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.</p>
Detects
T1557 Adversary-in-the-Middle
Part of
DET0296 Detect Adversary-in-the-Middle via Network and Configuration Anomalies

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:FlowUnexpected route changes or duplicate gateway advertisementsDC0078 Network Traffic Flow
networkdevice:configConfiguration file modified or replaced on network deviceDC0061 File Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
RoutingPolicyBaselineExpected routing and BGP/OSPF paths for validation.
FirmwareChecksumBaseline image checksum per device type used to detect tampering.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-5591Fortinet FortiOSMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale