{"id":"T1669","name":"Wi-Fi Networks","url":"https://attack.mitre.org/techniques/T1669","tactics":["initial-access"],"platforms":["Linux","Network Devices","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0536","stix_id":"x-mitre-detection-strategy--f9c29db2-8790-4255-957f-9a02f1d8d024","name":"Detection Strategy for Wi-Fi Networks","url":"https://attack.mitre.org/detectionstrategies/DET0536","analytics":[{"id":"AN1476","stix_id":"x-mitre-analytic--8586fd06-9801-473e-8ea6-d3da0ec82267","name":"Analytic 1476","description":"Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.","url":"https://attack.mitre.org/detectionstrategies/DET0536#AN1476","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Microsoft-Windows-WLAN-AutoConfig","channel":"EventCode=8001, 8002, 8003","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-microsoft-windows-wlan-autoconfig"},{"name":"WinEventLog:Security","channel":"EventCode=4776, 4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"KnownSSIDList","description":"Defines approved Wi-Fi SSIDs for the environment; deviations may indicate malicious connection attempts."},{"field":"GeoLocationContext","description":"Correlates expected physical location of systems with observed Wi-Fi connections to detect anomalies."}],"live":true,"detection_strategies":["DET0536"],"techniques":["T1669"]},{"id":"AN1477","stix_id":"x-mitre-analytic--6ad3d8bb-fc6f-45fb-b44e-871c263230d8","name":"Analytic 1477","description":"Detects unauthorized wireless associations by monitoring wpa_supplicant logs, NetworkManager events, and system calls related to interface state changes. Anomalies include repeated association failures, new SSIDs outside baselined values, and rogue AP connections.","url":"https://attack.mitre.org/detectionstrategies/DET0536#AN1477","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"New Wi-Fi connection established or repeated association failures","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-syslog"},{"name":"auditd:SYSCALL","channel":"ioctl: Changes to wireless network interfaces (up, down, reassociate)","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"AllowedSSIDRegex","description":"Regex-based whitelist of corporate SSIDs; anomalous matches indicate suspicious activity."},{"field":"RetryThreshold","description":"Number of failed association attempts allowed before triggering detection."}],"live":true,"detection_strategies":["DET0536"],"techniques":["T1669"]},{"id":"AN1478","stix_id":"x-mitre-analytic--20c2cbdf-2a02-40d1-9d10-b91d9bbe3004","name":"Analytic 1478","description":"Detects unauthorized Wi-Fi associations and SSID scanning activity using unified logs and airport command telemetry. Anomalies include rapid SSID switching, connections to unapproved SSIDs, or repeated authentication failures.","url":"https://attack.mitre.org/detectionstrategies/DET0536#AN1478","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Association and authentication events including failures and new SSIDs","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"query: Historical list of associated SSIDs compared against baseline","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"BaselineSSIDHistory","description":"Historical record of corporate SSID associations per device; deviations may indicate rogue AP usage."}],"live":true,"detection_strategies":["DET0536"],"techniques":["T1669"]},{"id":"AN1479","stix_id":"x-mitre-analytic--8ea556b8-d6d3-430c-a438-847b00e607a5","name":"Analytic 1479","description":"Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points.","url":"https://attack.mitre.org/detectionstrategies/DET0536#AN1479","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Firewall","channel":"rule_modification: New or modified firewall rules related to wireless interfaces","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"nsm-firewall"},{"name":"WIDS:AssociationLogs","channel":"Unauthorized AP or anomalous MAC address connection attempts","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"wids-associationlogs"}],"mutable_elements":[{"field":"AuthorizedAPList","description":"Defines known access points and MAC addresses; deviations highlight rogue or unauthorized devices."}],"live":true,"detection_strategies":["DET0536"],"techniques":["T1669"]}],"live":true,"version":"1.0","techniques":["T1669"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}