{"id":"T1557.002","name":"ARP Cache Poisoning","url":"https://attack.mitre.org/techniques/T1557/002","tactics":["credential-access","collection"],"platforms":["Linux","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0387","stix_id":"x-mitre-detection-strategy--99758bfb-f638-43aa-a233-d27646452116","name":"Detect ARP Cache Poisoning Across Linux, Windows, and macOS","url":"https://attack.mitre.org/detectionstrategies/DET0387","analytics":[{"id":"AN1091","stix_id":"x-mitre-analytic--dc4a80e3-7670-474f-aaf6-c051d5dda83c","name":"Analytic 1091","description":"Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices.","url":"https://attack.mitre.org/detectionstrategies/DET0387#AN1091","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"ARP cache modification attempts observed through event tracing or security baselines","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TrustedGatewayMAC","description":"Expected MAC address for default gateways; deviations may indicate poisoning."},{"field":"TimeWindow","description":"Correlation interval for repeated unsolicited ARP replies."}],"live":true,"detection_strategies":["DET0387"],"techniques":["T1557.002"]},{"id":"AN1092","stix_id":"x-mitre-analytic--5ee16525-5e86-4634-aa75-37468c4034c4","name":"Analytic 1092","description":"Detects suspicious gratuitous ARP responses or inconsistent IP-to-MAC mappings using auditd and packet capture. Behavioral focus is on unsolicited replies overriding legitimate ARP ownership.","url":"https://attack.mitre.org/detectionstrategies/DET0387#AN1092","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"setsockopt, ioctl modifying ARP entries","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Gratuitous ARP replies with mismatched IP-MAC binding","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedARPUpdates","description":"Expected legitimate IP-to-MAC updates for servers or virtual routers."},{"field":"AlertThreshold","description":"Number of anomalous ARP packets per second before triggering detection."}],"live":true,"detection_strategies":["DET0387"],"techniques":["T1557.002"]},{"id":"AN1093","stix_id":"x-mitre-analytic--0f996058-7524-4759-9d88-a8997e90ff3c","name":"Analytic 1093","description":"Detects anomalous ARP cache changes and unsolicited ARP broadcasts using unified logs and packet capture. Behavioral detection includes multiple IP addresses mapped to the same MAC address and repeated gratuitous ARP traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0387#AN1093","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"ARP table updates inconsistent with expected gateway or DHCP lease assignments","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Excessive gratuitous ARP replies on local subnet","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"GatewayMACBaseline","description":"Known MAC addresses for gateways or DHCP servers; used to detect spoofed ARP entries."},{"field":"CorrelationDepth","description":"How many ARP inconsistencies to tolerate before escalating detection."}],"live":true,"detection_strategies":["DET0387"],"techniques":["T1557.002"]}],"live":true,"version":"1.0","techniques":["T1557.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}