{"id":"T1557.004","name":"Evil Twin","url":"https://attack.mitre.org/techniques/T1557/004","tactics":["credential-access","collection"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0379","stix_id":"x-mitre-detection-strategy--b376d299-69ef-444a-8ba1-15a6c7049605","name":"Detect Evil Twin Wi-Fi Access Points on Network Devices","url":"https://attack.mitre.org/detectionstrategies/DET0379","analytics":[{"id":"AN1069","stix_id":"x-mitre-analytic--670462e3-6c3e-4779-af75-2a0424a5d221","name":"Analytic 1069","description":"Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs.","url":"https://attack.mitre.org/detectionstrategies/DET0379#AN1069","platforms":["Network Devices"],"log_source_references":[{"name":"WLANLogs:Association","channel":"Multiple APs advertising the same SSID but with different BSSID/MAC or encryption type","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"wlanlogs-association"},{"name":"NSM:Flow","channel":"Probe responses from unauthorized APs responding to client probe requests","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"networkdevice:syslog","channel":"Failed authentication requests redirected to non-standard portals","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"KnownSSIDs","description":"Baseline of authorized SSIDs; deviations may indicate rogue AP."},{"field":"AllowedBSSIDs","description":"Whitelist of BSSID/MAC addresses mapped to corporate SSIDs."},{"field":"SignalStrengthThreshold","description":"Used to flag unusually strong signals from unexpected APs."},{"field":"CaptivePortalDomains","description":"Trusted login domains; unrecognized portals may be malicious."}],"live":true,"detection_strategies":["DET0379"],"techniques":["T1557.004"]}],"live":true,"version":"1.0","techniques":["T1557.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}