{"id":"T1040","name":"Network Sniffing","url":"https://attack.mitre.org/techniques/T1040","tactics":["credential-access","discovery"],"platforms":["IaaS","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0314","stix_id":"x-mitre-detection-strategy--49505f6d-b778-4a84-a072-9236b700e7b5","name":"Detection Strategy for Network Sniffing Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0314","analytics":[{"id":"AN0875","stix_id":"x-mitre-analytic--b3579b0f-7daf-40bd-af1c-f5cd020942e6","name":"Analytic 0875","description":"Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.","url":"https://attack.mitre.org/detectionstrategies/DET0314#AN0875","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"ToolNames","description":"Adjust list of known sniffing tools based on environment and known administrator usage."},{"field":"TimeWindow","description":"Tune time of day or frequency of capture sessions to reduce false positives from authorized use."}],"live":true,"detection_strategies":["DET0314"],"techniques":["T1040"]},{"id":"AN0876","stix_id":"x-mitre-analytic--01ef3337-0585-4eaa-acb2-df363f7d5463","name":"Analytic 0876","description":"Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0314#AN0876","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve, setifflags","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"promiscuous mode transitions (ioctl or ifconfig)","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"networkconfig ","channel":"interface flag PROMISC, netstat | ip link | ethtool","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"networkconfig"}],"mutable_elements":[{"field":"InterfaceList","description":"Limit analysis to external interfaces (e.g., eth0, wlan0) and exclude virtual adapters."},{"field":"PromiscuousSessionThreshold","description":"Raise alerts if interface remains in PROMISC longer than threshold duration."}],"live":true,"detection_strategies":["DET0314"],"techniques":["T1040"]},{"id":"AN0877","stix_id":"x-mitre-analytic--31098e90-e2a0-477f-80ca-e969430d54c2","name":"Analytic 0877","description":"Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries.","url":"https://attack.mitre.org/detectionstrategies/DET0314#AN0877","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"eventMessage = 'promiscuous'","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events where path like '%tcpdump%'","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"fs:fsusage","channel":"access to BPF devices or interface IOCTLs","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"AllowedTools","description":"Whitelist Apple-native tools used by IT admins and mobile device management (MDM)."},{"field":"UserContext","description":"Prioritize detections from non-admin or low-privilege users performing packet captures."}],"live":true,"detection_strategies":["DET0314"],"techniques":["T1040"]},{"id":"AN0878","stix_id":"x-mitre-analytic--4c4941eb-b087-4710-8c88-ff537c2309ff","name":"Analytic 0878","description":"Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment.","url":"https://attack.mitre.org/detectionstrategies/DET0314#AN0878","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"CreateTrafficMirrorSession / ModifyTrafficMirrorTarget","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"MirrorSourceList","description":"Identify VMs or containers where mirror sessions are abnormal or unexpected."},{"field":"TargetIAMRole","description":"Monitor whether mirror target roles match administrative expectations."}],"live":true,"detection_strategies":["DET0314"],"techniques":["T1040"]},{"id":"AN0879","stix_id":"x-mitre-analytic--25403649-ce66-4fb0-9957-8c319b10e9d7","name":"Analytic 0879","description":"Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.","url":"https://attack.mitre.org/detectionstrategies/DET0314#AN0879","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"admin login events","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"},{"name":"networkdevice:syslog","channel":"exec command='monitor capture'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"},{"name":"networkdevice:syslog","channel":"config change (e.g., logging buffered, pcap buffers)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"AdminSessionDuration","description":"Tunable alerting threshold for interactive CLI sessions."},{"field":"CaptureCommandList","description":"Define set of known capture/debug commands per vendor to flag unexpected usage."}],"live":true,"detection_strategies":["DET0314"],"techniques":["T1040"]}],"live":true,"version":"1.0","techniques":["T1040"]}],"sigma_rules":[{"id":"42b1a5b8-353f-4f10-b256-39de4467faff","title":"Harvesting Of Wifi Credentials Via Netsh.EXE","author":"Andreas Hunkeler (@Karneades), oscd.community","status":"test","level":"medium","date":"2020-04-20","modified":"2023-02-13","description":"Detect the harvesting of wifi credentials using netsh.exe","references":["https://blog.malwarebytes.com/threat-analysis/2020/04/new-agenttesla-variant-steals-wifi-credentials/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.credential-access","attack.t1040"],"path":"rules/windows/process_creation/proc_creation_win_netsh_wifi_credential_harvesting.yml","techniques":["T1040"],"cves":[]},{"id":"7b687634-ab20-11ea-bb37-0242ac130002","title":"Windows Pcap Drivers","author":"Cian Heasley","status":"test","level":"medium","date":"2020-06-10","modified":"2023-04-14","description":"Detects Windows Pcap driver installation based on a list of associated .sys files.","references":["https://ragged-lab.blogspot.com/2020/06/capturing-pcap-driver-installations.html#more"],"logsource":{"product":"windows","service":"security"},"tags":["attack.discovery","attack.credential-access","attack.t1040"],"path":"rules/windows/builtin/security/win_security_pcap_drivers.yml","techniques":["T1040"],"cves":[]},{"id":"adc9bcc4-c39c-4f6b-a711-1884017bf043","title":"Network Sniffing - MacOs","author":"Alejandro Ortuno, oscd.community","status":"test","level":"informational","date":"2020-10-14","modified":"2022-11-26","description":"Detects the usage of tooling to sniff network traffic.\nAn adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1040/T1040.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.discovery","attack.credential-access","attack.t1040"],"path":"rules/macos/process_creation/proc_creation_macos_network_sniffing.yml","techniques":["T1040"],"cves":[]},{"id":"b9e1f193-d236-4451-aaae-2f3d2102120d","title":"Cisco Sniffing","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-11","modified":"2023-01-04","description":"Show when a monitor or a span/rspan is setup or modified","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.credential-access","attack.discovery","attack.t1040"],"path":"rules/network/cisco/aaa/cisco_cli_net_sniff.yml","techniques":["T1040"],"cves":[]},{"id":"ba1f7802-adc7-48b4-9ecb-81e227fddfd5","title":"Potential Network Sniffing Activity Using Network Tools","author":"Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2019-10-21","modified":"2023-02-20","description":"Detects potential network sniffing via use of network tools such as \"tshark\", \"windump\".\nNetwork sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection.\nAn adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1040/T1040.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.discovery","attack.t1040"],"path":"rules/windows/process_creation/proc_creation_win_susp_network_sniffing.yml","techniques":["T1040"],"cves":[]},{"id":"d3c3861d-c504-4c77-ba55-224ba82d0118","title":"New Network Trace Capture Started Via Netsh.EXE","author":"Kutepov Anton, oscd.community","status":"test","level":"medium","date":"2019-10-24","modified":"2023-02-13","description":"Detects the execution of netsh with the \"trace\" flag in order to start a network capture","references":["https://blogs.msdn.microsoft.com/canberrapfe/2012/03/30/capture-a-network-trace-without-installing-anything-capture-a-network-trace-of-a-reboot/","https://klausjochem.me/2016/02/03/netsh-the-cyber-attackers-tool-of-choice/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.credential-access","attack.t1040"],"path":"rules/windows/process_creation/proc_creation_win_netsh_packet_capture.yml","techniques":["T1040"],"cves":[]},{"id":"da34e323-1e65-42db-83be-a6725ac2caa3","title":"Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock","author":"frack113","status":"test","level":"medium","date":"2024-05-12","modified":null,"description":"Detects the execution of powershell scripts with calls to the \"Start-NetEventSession\" cmdlet. Which allows an attacker to start event and packet capture for a network event session.\nAdversaries may attempt to capture network to gather information over the course of an operation.\nData captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/5f866ca4517e837c4ea576e7309d0891e78080a8/atomics/T1040/T1040.md#atomic-test-16---powershell-network-sniffing","https://github.com/0xsyr0/Awesome-Cybersecurity-Handbooks/blob/7b8935fe4c82cb64d61343de1a8b2e38dd968534/handbooks/10_post_exploitation.md","https://github.com/forgottentq/powershell/blob/9e616363d497143dc955c4fdce68e5c18d28a6cb/captureWindows-Endpoint.ps1#L13"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.credential-access","attack.discovery","attack.t1040"],"path":"rules/windows/powershell/powershell_script/posh_ps_packet_capture.yml","techniques":["T1040"],"cves":[]},{"id":"f4d3748a-65d1-4806-bd23-e25728081d01","title":"Network Sniffing - Linux","author":"Timur Zinniatullin, oscd.community","status":"test","level":"low","date":"2019-10-21","modified":"2022-12-18","description":"Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection.\nAn adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1040/T1040.md"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.credential-access","attack.discovery","attack.t1040"],"path":"rules/linux/auditd/execve/lnx_auditd_network_sniffing.yml","techniques":["T1040"],"cves":[]},{"id":"f956c7c1-0f60-4bc5-b7d7-b39ab3c08908","title":"PktMon.EXE Execution","author":"frack113","status":"test","level":"medium","date":"2022-03-17","modified":"2023-06-23","description":"Detects execution of PktMon, a tool that captures network packets.","references":["https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.credential-access","attack.t1040"],"path":"rules/windows/process_creation/proc_creation_win_pktmon_execution.yml","techniques":["T1040"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-32030","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-1040","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}