Detailedseverity: MediumDraft
CAPEC-158Sniffing Network Traffic
Abstraction
Detailed
Status
Draft
Severity
Medium
Description
In this attack pattern, the adversary monitors network traffic between nodes of a public or multicast network in an attempt to capture sensitive information at the protocol level. Network sniffing applications can reveal TCP/IP, DNS, Ethernet, and other low-level network communication information. The adversary takes a passive role in this attack pattern and simply observes and analyzes the traffic. The adversary may precipitate or indirectly influence the content of the observed transaction, but is never the intended recipient of the target information.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 2
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Encryption of Sensitive Datacwe-311 | 100% | live |
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Multi-Factor Authentication Interceptiont1111 | 100% | live |
| Technique | Network Sniffingt1040 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.