Compliance Node Overview
MITRE ATT&CK T1557.002 (ARP Cache Poisoning) is an Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices. This activity may be used to enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation. The ARP protocol is used to resolve IPv4 addresses to link layer addresses, such as a media access control (MAC) address. Devices in a local network segment communicate with each other by using link layer addresses. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1041 Encrypt Sensitive Information, M1031 Network Intrusion Prevention, M1017 User Training, M1042 Disable or Remove Feature or Program, M1035 Limit Access to Resource Over Network, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-16, AC-17, AC-18, AC-19, AC-20, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1557/002/
SHA-256 integrity: bd0dffbc448abcaa355816d4734caafce68a9b5fcc5f0af1d1a95789db2937bc
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1557.002: ARP Cache Poisoning (https://attack.mitre.org/techniques/T1557/002/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access