kevmap

TechniquesT1040 › AN0875

AN0875 Analytic 0875

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.</p>
Detects
T1040 Network Sniffing
Part of
DET0314 Detection Strategy for Network Sniffing Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4688DC0032 Process Creation
WinEventLog:SystemEventCode=7045DC0060 Service Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ToolNamesAdjust list of known sniffing tools based on environment and known administrator usage.
TimeWindowTune time of day or frequency of capture sessions to reduce false positives from authorized use.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-32030ASUS RoutersMapped
CVE-2022-1040Sophos FirewallMapped