Skip to content
← LibraryTechnique entry
T1040Credential Access

Network Sniffing

Passive capture of network traffic to extract credentials, tokens, configuration data — Wireshark, tcpdump, RTP / Modbus / Zigbee captures.

§ Where this technique fits

T1040 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 8 approved dossiers in the registry, typically at step 2.6 on average.

Authoritative reference: attack.mitre.org/techniques/T1040/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Modbus TCP Write to PLC
    OT-MODBUS-WRITE · Impact
    seen 2×
  2. 02
    Adversary-in-the-Middle
    T1557 · Credential Access
    seen 1×
  3. 03seen 1×
  4. 04seen 1×
  5. 05
    GTP-U User-Plane Spoof
    5G-GTP-U · Lateral Movement
    seen 1×
  6. 06
    HL7 v2 Message Injection
    HC-HL7-INJECT · Impact
    seen 1×
  7. 07
    Mifare Classic Key Recovery
    NFC-MIFARE-CRACK · Credential Access
    seen 1×