166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

AiTM

Tehnika u centru, pretnje koje je koriste levo, odbrane koje je suzbijaju desno. Ispod kartice — profil tehnike: gde se javlja i kako se prepoznaje.

← Threats that use it3

Threats that use it. Klik vodi na stranicu pojma.

technique · № 009 · initial access

AiTM

AiTM sits between the user and the real service. Classic phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that looks exactly like the real login (because it forwards everything to the real site), enters credentials and even the MFA code — the proxy passes them through, the real service issues a session token, and the attacker captures that token.

→ profil tehnike · gde se javlja i kako se prepoznaje
faza lancaPočetni pristup
MITRE ATT&CKT1557
detekcijaTragovi su promene ARP i DNS zapisa, isti IP sa više MAC adresa, novi mrežni prolaz i nepoznate pristupne tačke sa poznatim imenom. Upozorenja na sertifikat i nagli prelazak na slabiji protokol dodatno pojačavaju sumnju.
učestalostČešća je na gostinskim i deljenim mrežama, konferencijama, u kafićima i ravnim internim mrežama bez segmentacije. Ređa je tamo gde su veze šifrovane, mreže segmentirane i pristupne tačke pod nadzorom.

↗ How it is countered6