{"id":"T1557.003","name":"DHCP Spoofing","url":"https://attack.mitre.org/techniques/T1557/003","tactics":["credential-access","collection"],"platforms":["Linux","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0468","stix_id":"x-mitre-detection-strategy--9f227978-8d56-406f-9d50-ef10aae1bf77","name":"Detect DHCP Spoofing Across Linux, Windows, and macOS","url":"https://attack.mitre.org/detectionstrategies/DET0468","analytics":[{"id":"AN1290","stix_id":"x-mitre-analytic--780021a3-d3e6-4c5b-a976-1c3715b990e2","name":"Analytic 1290","description":"Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0468#AN1290","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=1341, 1342, 1020, 1063","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-system"},{"name":"NSM:Flow","channel":"DHCP OFFER or ACK with unauthorized DNS/gateway parameters","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AuthorizedDHCPServers","description":"List of known DHCP servers; unexpected sources are suspicious."},{"field":"TimeWindow","description":"Interval to correlate DHCP OFFER/ACK anomalies with subsequent misconfigurations."}],"live":true,"detection_strategies":["DET0468"],"techniques":["T1557.003"]},{"id":"AN1291","stix_id":"x-mitre-analytic--05d8ce15-eaeb-47f5-abb7-8f8868dd8aaa","name":"Analytic 1291","description":"Detects rogue DHCP activity by monitoring syslog for dhclient messages assigning unauthorized DNS/gateway values. Packet capture or IDS can detect multiple competing DHCP OFFERs from non-authorized servers.","url":"https://attack.mitre.org/detectionstrategies/DET0468#AN1291","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"suspicious DHCP lease assignment with unexpected DNS or gateway","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"NSM:Flow","channel":"Gratuitous or duplicate DHCP OFFER packets from non-legitimate servers","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedDHCPMACs","description":"Expected MAC addresses of DHCP servers on subnet."},{"field":"DHCPLeaseChangeThreshold","description":"Number of suspicious DHCP leases before raising an alert."}],"live":true,"detection_strategies":["DET0468"],"techniques":["T1557.003"]},{"id":"AN1292","stix_id":"x-mitre-analytic--4f2bc468-a57d-44e9-b9cd-d491df6b0daf","name":"Analytic 1292","description":"Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0468#AN1292","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"new DHCP configuration with anomalous DNS or router values","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Multiple DHCP OFFER responses for a single DISCOVER","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BaselineDNS","description":"Expected DNS server list; deviations may indicate spoofing."},{"field":"AlertSensitivity","description":"Threshold for number of anomalous DHCP responses before alerting."}],"live":true,"detection_strategies":["DET0468"],"techniques":["T1557.003"]}],"live":true,"version":"1.0","techniques":["T1557.003"]}],"sigma_rules":[{"id":"b07e58cf-cacc-4135-8473-ccb2eba63dd2","title":"Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-20","modified":null,"description":"Detects modifications to DNS records in Active Directory where the Distinguished Name (DN) contains a base64-encoded blob\nmatching the pattern \"1UWhRCAAAAA...BAAAA\". This pattern corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure,\ncommonly used in Kerberos coercion attacks. Adversaries may exploit this to coerce victim systems into authenticating to\nattacker-controlled hosts by spoofing SPNs via DNS. It is one of the strong indicators of a Kerberos coercion attack,.\nwhere adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.\nPlease investigate the user account that made the changes, as it is likely a low-privileged account that has been compromised.\n","references":["https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025"],"logsource":{"product":"windows","service":"security"},"tags":["attack.collection","attack.credential-access","attack.t1557.003","attack.persistence","attack.privilege-escalation"],"path":"rules/windows/builtin/security/win_security_kerberos_coercion_via_dns_object.yml","techniques":["T1557.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}