Esc
Traffic Duplication - T1020.001
(ATT&CK® Technique)
Definition
Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for some devices, often used for network analysis. For example, devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.