Techniques › T1040 › AN0875
AN0875 Analytic 0875
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.</p>
- Detects
- T1040 Network Sniffing
- Part of
- DET0314 Detection Strategy for Network Sniffing Across Platforms
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4688 | DC0032 Process Creation |
| WinEventLog:System | EventCode=7045 | DC0060 Service Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ToolNames | Adjust list of known sniffing tools based on environment and known administrator usage. |
TimeWindow | Tune time of day or frequency of capture sessions to reduce false positives from authorized use. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2021-32030 | ASUS Routers | Mapped |
| CVE-2022-1040 | Sophos Firewall | Mapped |