1200KM / detection
T1040 Network Sniffing — Detection Rules
Detection workspace for T1040 Network Sniffing: 9 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Network Sniffing - Linux · test · low · {"product":"linux","service":"auditd"}
- Network Sniffing - MacOs · test · informational · {"category":"process_creation","product":"macos"}
- Cisco Sniffing · test · medium · {"product":"cisco","service":"aaa"}
- Windows Pcap Drivers · test · medium · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- New Network Trace Capture Started Via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Harvesting Of Wifi Credentials Via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- PktMon.EXE Execution · test · medium · {"category":"process_creation","product":"windows"}
- Potential Network Sniffing Activity Using Network Tools · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0314 Detection Strategy for Network Sniffing Across Platforms
AN0875 Analytic 0875
Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.
AN0876 Analytic 0876
Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions.
AN0877 Analytic 0877
Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries.
AN0878 Analytic 0878
Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment.
AN0879 Analytic 0879
Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.