166 terms · 75/46/45
Technique № 028 · class: discovery

Network Sniffing

Passively intercepting network traffic to collect sensitive data.

Term

description · examples · notes

Passively intercepting network traffic to collect sensitive data.

Description

Uses tools like Wireshark, tcpdump, or specialized hardware taps.

Effective in networks without encryption or with compromised TLS.

Can capture credentials, session tokens, email content, and API keys.

ARP spoofing or SPAN ports can extend the interception scope.

Examples

  • Wireshark for analyzing HTTP traffic on open WiFi
  • ARP spoofing for MitM on local network

Notes

  • Passive discovery technique; differs from active scanning.

Mentioned in the news

Composite

Threats

used by 2

Threats that use it. Select one to open its page.

Defenses

countered by 6