Wi-Fi Networks Attack Analysis: T1669 – Rogue Access Point & Evil Twin
SIEM Alert Details: Wireless Intrusion Detection Alert ID: SIEM-WIDS-ROGUEAP-7842Alert Time: 2024-01-30 14:18:32 ESTSeverity: HIGH (85/100)Source: Aruba Wireless Intrusion Detection System (WIDS) + Splunk CorrelationRule: “Rogue Access Point with Corporate SSID Spoofing”MITRE ATT&CK: T1669 – Wi-Fi NetworksSub-technique: T1669.001 – Evil Twin Attack Alert Details: Primary Detection Source: Aruba WIDS Sensor (Location: Building 1, Floor 3) Secondary Detection: Cisco Identity Services Engine (ISE) RADIUS … Read more