Skip to content

DET0743 Detection of Wireless Sniffing

Item Value
ID DET0743
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T0887 (Wireless Sniffing)

Analytics

ICS

AN1876

Purely passive network sniffing cannot be detected effectively. In cases where the adversary interacts with the wireless network (e.g., joining a Wi-Fi network) detection may be possible. Monitor for new or irregular network traffic flows which may indicate potentially unwanted devices or sessions on wireless networks. In Wi-Fi networks monitor for changes such as rogue access points or low signal strength, indicating a device is further away from the access point then expected and changes in the physical layer signal.(Citation: Nzyme Alerts Intro) (Citation: Wireless Intrusion Detection) Network traffic content will provide important context, such as hardware (e.g., MAC) addresses, user accounts, and types of messages sent.

Log Sources
Data Component Name Channel
Network Traffic Flow (DC0078) Network Traffic None
Mutable Elements
Field Description