Skip to content

attack map

sloth wiki-sync edited this page Sep 30, 2026 · 1 revision

Attack map

Summary: Cross-reference table from threat class → which sloth view (or wiki concept page) is the right entry point.

Sources: docs/views/README.md, docs/views/alerts.md, all per-view docs.

Last updated: 2026-05-25.


Network-layer attacks

Threat Start here
DGA / DNS tunnelling dns.md, alerts (NXDOMAIN_BURST)
TLS downgrade / weak crypto tls.md, ja3-fingerprinting
Implant / C2 fingerprint ja3-fingerprinting, beacon-detection
ARP spoofing / MITM arp.md
Rogue DHCP dhcp.md
Port scan alerts (PORT_SCAN)
Credential stuffing on HTTP http.md
Threat-intel domain / IP hit threat-intel, alerts
Responder / LLMNR poisoning nbns.md
UPnP-IGD abuse / CallStranger ssdp.md
NTP amplification ntp.md
ICMP tunnel / RA flood icmp.md

WiFi / 802.11 attacks

Threat Start here
Evil-twin / rogue AP beacons.md, deauth.md, wifi-sigint
WPA capture / PMKID harvest eapol.md, wifi-sigint
Deauth-driven handshake harvest deauth.md + eapol.md
Hidden-SSID disclosure beacons.md (revealed * rows)
Probe-request PNL leakage probe.md, pnl.md
MAC-randomisation deanonymisation mac-randomisation, seqnum.md, pnl.md
KARMA / mana — auto-respond to every probe pnl.md, assoc.md
Beacon flood (mdk3/4) beacons.md

Triage tips

  • Bold IP across multiple dashboard panels → start with connections.md and pivot to packets.md.
  • Sustained CRIT alert → the alert footer shows RIR + hosting-org enrichment; the alert key already names the IP / domain.
  • WiFi anomaly → run the four wifi-sigint views side-by-side; they're designed to compose.

Related pages

Clone this wiki locally