Skip to content
← LibraryTechnique entry
N-ARP-SPOOFCredential Access

ARP Spoofing / Cache Poisoning

bettercap / ettercap to interpose between two hosts on the same broadcast — captures cleartext + downgrades TLS where possible.

§ Where this technique fits

N-ARP-SPOOF is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Network Sniffing
    T1040 · Credential Access
    seen 1×
  2. 02
    RTP Stream Capture
    VOIP-RTP-CAPTURE · Collection
    seen 1×