{"id":"T1557","name":"Adversary-in-the-Middle","url":"https://attack.mitre.org/techniques/T1557","tactics":["credential-access","collection"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0296","stix_id":"x-mitre-detection-strategy--0eb48c77-9056-4178-900b-7ac23fd1c7cd","name":"Detect Adversary-in-the-Middle via Network and Configuration Anomalies","url":"https://attack.mitre.org/detectionstrategies/DET0296","analytics":[{"id":"AN0823","stix_id":"x-mitre-analytic--c15f60a8-6e58-460f-8dcf-1bce272b5eaf","name":"Analytic 0823","description":"Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.","url":"https://attack.mitre.org/detectionstrategies/DET0296#AN0823","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredRegistryPaths","description":"Specific network stack and DNS registry keys that vary by enterprise configuration."},{"field":"DowngradeCipherList","description":"List of weak/legacy ciphers tuned per environment for TLS downgrade detection."},{"field":"TimeWindow","description":"Correlation period between config changes and abnormal network connections."}],"live":true,"detection_strategies":["DET0296"],"techniques":["T1557"]},{"id":"AN0824","stix_id":"x-mitre-analytic--3cdef7d3-4ca6-4d4a-933b-656af73f8433","name":"Analytic 0824","description":"Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.","url":"https://attack.mitre.org/detectionstrategies/DET0296#AN0824","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Unexpected ARP replies or DNS responses inconsistent with authoritative servers","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredFiles","description":"List of system files shaping traffic flow (hosts, resolv.conf, PAM modules)."},{"field":"ARPThreshold","description":"Rate/volume thresholds for ARP/DNS anomalies tuned per subnet."}],"live":true,"detection_strategies":["DET0296"],"techniques":["T1557"]},{"id":"AN0825","stix_id":"x-mitre-analytic--7535f2e7-d7bb-4e92-8a63-36cd9ccc01be","name":"Analytic 0825","description":"Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.","url":"https://attack.mitre.org/detectionstrategies/DET0296#AN0825","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Configuration profile modified or new profile installed","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"TLS downgrade or inconsistent DNS answers","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProfileIdentifiers","description":"Known good vs suspicious configuration profiles per enterprise baseline."},{"field":"TLSVersionThreshold","description":"Minimum TLS version accepted in network traffic inspection."}],"live":true,"detection_strategies":["DET0296"],"techniques":["T1557"]},{"id":"AN0826","stix_id":"x-mitre-analytic--bb3daf14-f237-4688-a319-a4d7570e407e","name":"Analytic 0826","description":"Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.","url":"https://attack.mitre.org/detectionstrategies/DET0296#AN0826","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Unexpected route changes or duplicate gateway advertisements","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"networkdevice:config","channel":"Configuration file modified or replaced on network device","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-config"}],"mutable_elements":[{"field":"RoutingPolicyBaseline","description":"Expected routing and BGP/OSPF paths for validation."},{"field":"FirmwareChecksum","description":"Baseline image checksum per device type used to detect tampering."}],"live":true,"detection_strategies":["DET0296"],"techniques":["T1557"]}],"live":true,"version":"1.0","techniques":["T1557"]}],"sigma_rules":[{"id":"2074e137-1b73-4e2d-88ba-5a3407dbdce0","title":"Notepad++ Updater DNS Query to Uncommon Domains","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-02-02","modified":"2026-03-16","description":"Detects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure.\nThis could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/dns_query/dns_query_win_gup_query_to_uncommon_domains.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"3b8f4c92-6a51-4d7e-9c3a-8e2d1f5a7b09","title":"Uncommon File Created by Notepad++ Updater Gup.EXE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-02-03","modified":"2026-03-16","description":"Detects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations.\nThis could indicate potential exploitation of the updater component to deliver unwanted malware or unwarranted files.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/file/file_event/file_event_win_gup_uncommon_file_creation.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"50e606bf-04ce-4ca7-9d54-3449494bbd4b","title":"Cisco LDP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":null,"description":"Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"ldp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/ldp/cisco_ldp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"56fa3cd6-f8d6-4520-a8c7-607292971886","title":"Cisco BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/bgp/cisco_bgp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"a557ffe6-ac54-43d2-ae69-158027082350","title":"Huawei BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"huawei","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/huawei/bgp/huawei_bgp_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43","title":"Juniper BGP Missing MD5","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"juniper","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/juniper/bgp/juniper_bgp_missing_md5.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"bb0e87ce-c89f-4857-84fa-095e4483e9cb","title":"Suspicious Child Process of Notepad++ Updater - GUP.Exe","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-02-03","modified":null,"description":"Detects suspicious child process creation by the Notepad++ updater process (gup.exe).\nThis could indicate potential exploitation of the updater component to deliver unwanted malware.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/process_creation/proc_creation_win_gup_susp_child_process.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]},{"id":"d22df9cd-2aee-4089-93c7-9dc4eae77f2c","title":"ISATAP Router Address Was Set","author":"hamid","status":"experimental","level":"medium","date":"2025-10-19","modified":null,"description":"Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6.\nIn such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic.\nThis detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.\n","references":["https://www.blackhillsinfosec.com/mitm6-strikes-again-the-dark-side-of-ipv6/","https://redfoxsec.com/blog/ipv6-dns-takeover/","https://www.securityhq.com/blog/malicious-isatap-tunneling-unearthed-on-windows-server/","https://medium.com/@ninnesoturan/detecting-ipv6-dns-takeover-a54a6a88be1f"],"logsource":{"product":"windows","service":"system"},"tags":["attack.impact","attack.credential-access","attack.collection","attack.initial-access","attack.privilege-escalation","attack.execution","attack.t1557","attack.t1565.002"],"path":"rules/windows/builtin/system/microsoft_windows_Iphlpsvc/win_system_isatap_router_address_set.yml","techniques":["T1557","T1565.002"],"cves":[]},{"id":"ea1a07f0-3dac-47a2-aeb4-86f5379ba2b4","title":"Azure Sign-In With Axios User Agent","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"low","date":"2026-04-28","modified":null,"description":"Detects sign-in attempts in Azure/Entra ID logs where the user agent contains \"axios\",\nindicating potential use of automated credential harvesting or AiTM phishing infrastructure.\nAxios is a Node.js HTTP client abused to intercept and replay stolen credentials and MFA tokens.\nWhen triaging results, analysts should:\n    - Check the sign-in risk level, MFA status, and conditional access results for signs of bypass.\n    - Look for sign-ins from unusual locations or IPs, especially if the same IP targets multiple accounts.\n    - Prioritize successful sign-ins over failed ones, as they may indicate a completed credential replay or AiTM attack.\n","references":["https://thehackernews.com/2025/09/axios-abuse-and-salty-2fa-kits-fuel.html","https://www.proofpoint.com/us/blog/threat-insight/http-client-tools-exploitation-account-takeover-attacks"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.credential-access","attack.collection","attack.t1557","detection.threat-hunting"],"path":"rules-threat-hunting/cloud/azure/signin_logs/azure_ad_signin_axios_user_agent.yml","techniques":["T1557"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-31201","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-31200","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-1040","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2019-5591","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}