kevmap

TechniquesT1020.001 › AN1132

AN1132 Analytic 1132

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unauthorized mirroring sessions initiated on routers/switches (e.g., via monitor session, mirror port) coupled with outbound traffic from mirrored interface to unexpected destinations.</p>
Detects
T1020.001 Traffic Duplication
Part of
DET0403 Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:syslogConfig change: CLI/NETCONF/SNMP – 'monitor session', 'mirror port'DC0078 Network Traffic Flow
networkdevice:FlowTraffic from mirrored interface to mirror target IPDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ConfigChangeTypeTune based on accepted interface config changes (e.g., audit only mirror session creation)
MirrorDestinationPortDefine high-risk ports used for exfil (e.g., 4443, 8443, 2055)
DeviceRoleDefine whether mirroring is expected on edge vs core vs distribution devices