How to Test Adversary-in-the-Middle Without Hacking Tools
ID: 1b9b3fcb-b06e-5196-a303-73633a545320
STIX ID: report--1b9b3fcb-b06e-5196-a303-73633a545320
Feed Name: Black Hills Infosec Blog
This webcast transcript explains Adversary‑in‑the‑Middle attacks and demonstrates how common multi‑factor authentication methods (SMS, TOTP, push notifications, phone calls, and many “passwordless” flows) can be phished or relayed to an attacker who then hijacks the victim’s session; the presenter shows live demos proving these weaknesses and contrasts them with FIDO2 passkeys, which use public‑key cryptography and local channels (USB/Bluetooth/NFC/TPM) and resist AiTM. Recommendations include testing MFA by attempting a remote login (if a login can be completed from a remote machine with the user’s help, the method is vulnerable), enabling and enrolling users in FIDO2/passkeys, disabling weak MFA options, and applying conditional access (IP/device restrictions or certificate‑based device authentication) while prioritizing high‑risk accounts for remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
