kevmap

TechniquesT1557.003 › AN1292

AN1292 Analytic 1292

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic.</p>
Detects
T1557.003 DHCP Spoofing
Part of
DET0468 Detect DHCP Spoofing Across Linux, Windows, and macOS

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlognew DHCP configuration with anomalous DNS or router valuesDC0038 Application Log Content
NSM:FlowMultiple DHCP OFFER responses for a single DISCOVERDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
BaselineDNSExpected DNS server list; deviations may indicate spoofing.
AlertSensitivityThreshold for number of anomalous DHCP responses before alerting.