1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1557.003 DHCP Spoofing — Attack Simulation

Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network. By achieving the adversary-in-the-middle (AiTM) position, adversaries may collect network communications, including passed credentials, especially those sent over insecure, unencrypted protocols. This may also enable follow-on behaviors such as Network…

Technique description

Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network. By achieving the adversary-in-the-middle (AiTM) position, adversaries may collect network communications, including passed credentials, especially those sent over insecure, unencrypted protocols. This may also enable follow-on behaviors such as Network…

No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.

Connected ecosystem references

Linked tags

Detection and collection

T1557.003 detection workspace

Attack tools

No reviewed association in this snapshot.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.