Detecting Arp Poisoning In Network Traffic

Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC mapping changes, and duplicate IP addresses. Use when investigating suspected man-in-the-middle interception or session hijacking on a local network segment, or when building layer-2 anomaly detection for a SOC.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-arp-poisoning-in-network-traffic commit 9fac77ae97

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-arp-poisoning-in-network-traffic