Network Sniffing - MacOs — Detection Rule

Detects the usage of tooling to sniff network traffic. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

Read the full analysis on IntelFusions