kevmap

TechniquesT1557.004 › AN1069

AN1069 Analytic 1069

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs.</p>
Detects
T1557.004 Evil Twin
Part of
DET0379 Detect Evil Twin Wi-Fi Access Points on Network Devices

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WLANLogs:AssociationMultiple APs advertising the same SSID but with different BSSID/MAC or encryption typeDC0078 Network Traffic Flow
NSM:FlowProbe responses from unauthorized APs responding to client probe requestsDC0085 Network Traffic Content
networkdevice:syslogFailed authentication requests redirected to non-standard portalsDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
KnownSSIDsBaseline of authorized SSIDs; deviations may indicate rogue AP.
AllowedBSSIDsWhitelist of BSSID/MAC addresses mapped to corporate SSIDs.
SignalStrengthThresholdUsed to flag unusually strong signals from unexpected APs.
CaptivePortalDomainsTrusted login domains; unrecognized portals may be malicious.