Sigma Rule Library

MITRE ATT&CK technique

Adversary-in-the-Middle detection rulesT1557

Adversary-in-the-Middle (T1557) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 21 community-maintained Sigma detection rules in the library mapped to T1557 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek, cisco.

Top products

Tactic