| ARP behavior |
One MAC mapped to multiple IPs |
Check ARP tables on endpoints and servers |
arp -a, arp -n, network scans |
Clear sign of ARP cache poisoning |
| Gateway integrity |
Unexpected change in gateway MAC address |
Continuously monitor ARP entries for gateway |
ARP monitoring tools, scripts |
High-confidence indicator of MITM attack |
| ARP traffic patterns |
High volume of unsolicited ARP replies |
Analyze ARP traffic for reply spikes without requests |
Packet capture, NDR platforms |
Indicates active poisoning or ARP flooding |
| Packet consistency |
Mismatch between ARP payload MAC and Ethernet header MAC |
Inspect packet-level ARP details |
Wireshark, deep packet inspection tools |
Detects forged ARP responses |
| Network behavior |
Sudden latency or unusual routing patterns |
Correlate performance issues with ARP changes |
Network monitoring tools, NDR |
Traffic is being intercepted or redirected |
| User-facing signals |
TLS certificate warnings or HTTPS errors |
Monitor endpoint alerts and browser warnings |
Endpoint monitoring, SIEM |
Early sign of active MITM interception |
| Switch-level validation |
Invalid ARP packets on untrusted ports |
Enable ARP validation at switch level |
Dynamic ARP Inspection with DHCP snooping |
Blocks spoofed ARP before reaching hosts |
| Critical asset protection |
Unauthorized ARP changes for key systems |
Lock IP to MAC mappings |
Static ARP entries |
Prevents poisoning of high-value targets |
| Network-wide visibility |
ARP anomalies linked with suspicious activity |
Correlate ARP events with authentication and traffic data |
NDR or XDR platforms |
Detects attacks that bypass switch controls |
| Defense in depth |
Encrypted traffic still being intercepted |
Validate encryption and monitor anomalies |
TLS, HSTS, VPN, traffic analysis |
Limits impact even if spoofing succeeds |