Wartiva Security Controls

ARP: 2 Checks

Wartiva's ARP controls: conflicting ARP table entries and ARP spoofing of the default gateway on the endpoint's local network segment.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 2 checks on this page

The endpoint's ARP table contents

Ensure No Conflicting ARP Table Entries Are Present

Low severity · Wartiva Security Controls · ARP

Finding: This IP address is claimed by more than one MAC address (ARP conflict).

This rule inspects a single ARP/neighbor cache entry. This rule fails when the entry's IP address is currently claimed by one or more other MAC (hardware) addresses on the same interface.

The conflicting entries are recorded on the entry itself as the endpoint's ARP table is collected, so the check reads only this entry. Conflicts are scoped per interface: a multi-homed host legitimately resolves the same private address to different hardware on different segments, and that is not a conflict.

Rationale: An IP address should resolve to exactly one hardware address on a given segment. Two MACs claiming one IP is either a duplicate-IP misconfiguration or the signature of ARP spoofing, in which an attacker injects forged ARP replies to redirect traffic.

Impact: Duplicate mappings cause intermittent connectivity loss and, when malicious, allow an attacker on the local segment to intercept or manipulate the victim's traffic.

Remediation

Investigate the duplicate IP-to-MAC mappings. Confirm whether two devices are misconfigured with the same IP address or whether one MAC is impersonating another (ARP spoofing). Reconcile DHCP reservations, correct any duplicate static IP assignments, and if impersonation is suspected, isolate the offending device and report it to your security team.

Risk
Reliability Impact
MITRE ATT&CK tactic
Credential Access (TA0006)

Evidence of ARP spoofing on the local segment

Ensure The Default Gateway Is Not Being ARP Spoofed

Critical severity · Wartiva Security Controls · ARP

Finding: The default gateway's IP address is claimed by more than one MAC address (possible ARP spoofing).

This rule finds ARP table entries for a device acting as a network gateway whose IP address another entry on the same endpoint and interface claims with a different MAC address. This rule fails for each such entry.

Rationale: In an ARP-poisoning (gateway-theft) attack, an adversary forges ARP replies so that the gateway's IP maps to the attacker's MAC, putting the attacker in the path of all off-subnet traffic. A gateway address claimed by more than one hardware address means the legitimate gateway and an impersonator are both present.

Impact: An attacker who spoofs the gateway can intercept, modify, or drop all traffic leaving the local network (adversary-in-the-middle), enabling credential theft and data exposure.

Note: This detects the contested state. A cache in which the attacker has fully overwritten the gateway entry with a single MAC is not detected here.

Remediation

Treat this as a potential man-in-the-middle attack on the default gateway. Verify the correct hardware address of your gateway or router, then remove or block the impersonating device from the network. On managed switches, enable Dynamic ARP Inspection (DAI) and DHCP snooping, and consider a static ARP entry for the gateway on critical hosts. Report the incident to your security team.

Risks
High Profile Threat, Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)