-
Notifications
You must be signed in to change notification settings - Fork 1
attack map
sloth wiki-sync edited this page Sep 30, 2026
·
1 revision
Summary: Cross-reference table from threat class → which sloth view (or wiki concept page) is the right entry point.
Sources: docs/views/README.md, docs/views/alerts.md, all per-view docs.
Last updated: 2026-05-25.
| Threat | Start here |
|---|---|
| DGA / DNS tunnelling |
dns.md, alerts (NXDOMAIN_BURST) |
| TLS downgrade / weak crypto | tls.md, ja3-fingerprinting |
| Implant / C2 fingerprint | ja3-fingerprinting, beacon-detection |
| ARP spoofing / MITM | arp.md |
| Rogue DHCP | dhcp.md |
| Port scan |
alerts (PORT_SCAN) |
| Credential stuffing on HTTP | http.md |
| Threat-intel domain / IP hit | threat-intel, alerts |
| Responder / LLMNR poisoning | nbns.md |
| UPnP-IGD abuse / CallStranger | ssdp.md |
| NTP amplification | ntp.md |
| ICMP tunnel / RA flood | icmp.md |
| Threat | Start here |
|---|---|
| Evil-twin / rogue AP | beacons.md, deauth.md, wifi-sigint |
| WPA capture / PMKID harvest | eapol.md, wifi-sigint |
| Deauth-driven handshake harvest | deauth.md + eapol.md |
| Hidden-SSID disclosure |
beacons.md (revealed * rows) |
| Probe-request PNL leakage | probe.md, pnl.md |
| MAC-randomisation deanonymisation | mac-randomisation, seqnum.md, pnl.md |
| KARMA / mana — auto-respond to every probe | pnl.md, assoc.md |
| Beacon flood (mdk3/4) | beacons.md |
- Bold IP across multiple dashboard panels → start with connections.md and pivot to packets.md.
- Sustained CRIT alert → the alert footer shows RIR + hosting-org enrichment; the alert key already names the IP / domain.
- WiFi anomaly → run the four wifi-sigint views side-by-side; they're designed to compose.
- alerts — the 61 alert rules and what each one keys on.
- threat-intel — the IOC list and its match semantics.
- ja3-fingerprinting — TLS-client identification primitive.
- beacon-detection — C2 periodicity detector.
- mac-randomisation — the seqnum deanonymisation primitive.
- wifi-sigint — the four 802.11 SIGINT views.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance