1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1557.003 DHCP Spoofing — Detection Rules

Detection workspace for T1557.003 DHCP Spoofing: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

  • Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation · experimental · high · {"product":"windows","service":"security","definition":"By default these events are not logged by default for MicrosoftDNS objects in Active Directory.\nTo enable detection, configure an AuditRule on the DNS object container with the \"CreateChild\" permission for the \"Everyone\" principal.\nThis can be accomplished using tools such as Set-AuditRule (see https://github.com/OTRF/Set-AuditRule).\n"}

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0468 Detect DHCP Spoofing Across Linux, Windows, and macOS

AN1290 Analytic 1290

Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints.

AN1291 Analytic 1291

Detects rogue DHCP activity by monitoring syslog for dhclient messages assigning unauthorized DNS/gateway values. Packet capture or IDS can detect multiple competing DHCP OFFERs from non-authorized servers.

AN1292 Analytic 1292

Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1557.003 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.