Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for some devices, often used for network analysis. For example, devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device. (Citation: Cisco Traffic Mirroring)(Citation: Juniper Traffic Mirroring) Adversaries may abuse traffic mirroring to mirror or redirect network traffic through other infrastructure they control. Malicious modifications to network devices to enable traffic redirection may be possible through [ROMMONkit](https://attack.mitre.org/techniques/T1542/004) or [Patch System Image](https://attack.mitre.org/techniques/T1601/001).(Citation: US-CERT-TA18-106A)(Citation: Cisco Blog Legacy Device Attacks) Many cloud-based environments also support traffic mirroring. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to.(Citation: AWS Traffic Mirroring)(Citation: GCP Packet Mirroring)(Citation: Azure Virtual Network TAP) Adversaries may use traffic duplication in conjunction with [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Input Capture](https://attack.mitre.org/techniques/T1056), or [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557) depending on the goals and objectives of the adversary.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices
is blocked by Encrypt Sensitive Information
is blocked by User Account Management
is blocked by Data Loss Prevention
is blocked by Asset Inventories
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Transmission Confidentiality
is blocked by Transmission Integrity
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Media & Data Retention
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Access Control For Mobile Devices
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Interconnection Security Agreements (ISAs)
is blocked by Remote Access
is blocked by Wireless Networking
is blocked by Information In Shared Resources
Impressum Deutsch Englisch