Network Sniffing

T1040

Technique.View on attack.mitre.org

About this technique

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

Data captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol. Techniques for name service resolution poisoning, such as Name Resolution Poisoning and SMB Relay, can also be used to capture credentials to websites, proxies, and internal systems by redirecting traffic to an adversary.

Network sniffing may reveal configuration details, such as running services, version numbers, and other network characteristics (e.g. IP addresses, hostnames, VLAN IDs) necessary for subsequent Lateral Movement and/or Stealth activities. Adversaries may likely also utilize network sniffing during Adversary-in-the-Middle (AiTM) to passively gain additional knowledge about the environment.

In cloud-based environments, adversaries may still be able to use traffic mirroring services to sniff network traffic from virtual machines. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to. Often, much of this traffic will be in cleartext due to the use of TLS termination at the load balancer level to reduce the strain of encrypting and decrypting traffic. The adversary can then use exfiltration techniques such as Transfer Data to Cloud Account in order to access the sniffed traffic.

On network devices, adversaries may perform network captures using Network Device CLI commands such as `monitor capture`.

Detection rules12

Rules on DetectionCode tagged with T1040.

Sigma9

RuleLevelLog source
Cisco Sniffingmediumcisco / NULL
Harvesting Of Wifi Credentials Via Netsh.EXEmediumwindows / process_creation
New Network Trace Capture Started Via Netsh.EXEmediumwindows / process_creation
PktMon.EXE Executionmediumwindows / process_creation
Potential Network Sniffing Activity Using Network Toolsmediumwindows / process_creation
Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlockmediumwindows / ps_script
Windows Pcap Driversmediumwindows / NULL
Network Sniffing - Linuxlowlinux / NULL
Network Sniffing - MacOsinformationalmacos / process_creation

Splunk3

RuleTypeRiskData source
Cisco ASA - Packet Capture ActivityAnomalyNULLCisco ASA Logs
Cisco SNMP Community String Configuration ChangesAnomalyNULLCisco IOS Logs
Windows Network Sniffing Tool ExecutedAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups8

Software17

Campaigns3

Procedure examples28

Groups8

Used byProcedure example
GroupAPT28

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

GroupAPT33

APT33 has used SniffPass to collect credentials by sniffing network traffic.

GroupDarkVishnya

DarkVishnya used network sniffing to obtain login data.

GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

GroupSalt Typhoon

Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces.

GroupSandworm Team

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

GroupUNC3886

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

GroupVelvet Ant

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

Software17

Used byProcedure example
MalwareCASTLETAP

CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic.

Malwarecd00r

cd00r can use the libpcap library to monitor captured packets for specifc sequences.

MalwareEmotet

Emotet has been observed to hook network APIs to monitor network traffic.

ToolEmpire

Empire can be used to conduct packet captures on target hosts.

MalwareFoggyWeb

FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor.

ToolImpacket

Impacket can be used to sniff network traffic via an interface or raw socket.

MalwareJ-magic

J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports.

MalwareJumbledPath

JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts.

View all 17 software examples

Campaigns3

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network between the local LAN and the power grid’s industrial control systems.

CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

CampaignRedPenguin

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

References7

  1. AWS Traffic Mirroring Open source
    Amazon Web Services. (n.d.). How Traffic Mirroring works. Retrieved March 17, 2022.
  2. Azure Virtual Network TAP Open source
    Microsoft. (2022, February 9). Virtual network TAP. Retrieved March 17, 2022.
  3. GCP Packet Mirroring Open source
    Google Cloud. (n.d.). Packet Mirroring overview. Retrieved March 17, 2022.
  4. Rhino Security Labs AWS VPC Traffic Mirroring Open source
    Spencer Gietzen. (2019, September 17). Abusing VPC Traffic Mirroring in AWS. Retrieved March 17, 2022.
  5. SpecterOps AWS Traffic Mirroring Open source
    Luke Paine. (2020, March 11). Through the Looking Glass — Part 1. Retrieved March 17, 2022.
  6. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  7. capture_embedded_packet_on_software Open source
    Cisco. (2022, August 17). Configure and Capture Embedded Packet on Software. Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.