Network sniffing is the practice of using a network interface on a computer system to monitor or capture information (Citation: Enterprise ATT&CK January 2018) regardless of whether it is the specified destination for the information. An adversary may attempt to sniff the traffic to gain information about the target. This information can vary in the level of importance. Relatively unimportant information is general communications to and from machines. Relatively important information would be login information. User credentials may be sent over an unencrypted protocol, such as Telnet, that can be captured and obtained through network packet analysis. In addition, ARP and Domain Name Service (DNS) poisoning can be used to capture credentials to websites, proxies, and internal systems by redirecting traffic to an adversary.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Workstation
is related to Control Server
is related to Remote Terminal Unit (RTU)
is related to Intelligent Electronic Device (IED)
is related to Firewall
is related to Application Server
is related to Data Historian
is related to Safety Controller
is related to Data Gateway
is related to Programmable Logic Controller (PLC)
is related to Human-Machine Interface (HMI)
is related to Distributed Control System (DCS) Controller
is related to Virtual Private Network (VPN) Server
is related to Jump Host
is related to Switch
is related to Programmable Automation Controller (PAC)
is blocked by Privileged Account Management
is blocked by Network Segmentation
is blocked by Multi-factor Authentication
is blocked by Detection of Network Sniffing
is blocked by Encrypt Network Traffic
is blocked by Static Network Configuration
Impressum German English