An adversary may collect message contents, credentials, identifiers, addressing information, timing, volumes, or other metadata from wired, wireless, virtual, or intermediary network points. It is primarily a confidentiality attack, although collected information can enable later attacks.
Plaintext can expose content directly. Sound end-to-end encryption can protect content in transit, but observable metadata may still reveal relationships and behavior. Compromised endpoints or keys, incorrectly authenticated sessions, or authorized intermediaries can expose plaintext despite encryption elsewhere.
Key points
Observation pointsExposure may occur on a local link, wireless channel, shared or compromised infrastructure, monitoring interface, intermediary service, or endpoint where communications are available in readable form.
Detection challengeA strictly passive observer sends no traffic and may be invisible to the endpoints. Investigations often focus on how access was obtained, sensor or account changes, key exposure, and resulting misuse.
Defensive prioritiesMinimize plaintext protocols, use authenticated end-to-end encryption where appropriate, protect keys and endpoints, control access to captures and telemetry, secure network infrastructure, and limit retained sensitive data.
Important limitationEncryption does not hide all metadata and cannot protect plaintext before encryption or after decryption. Link encryption may also leave content visible at intermediate systems, and a compromised endpoint can bypass transport protections entirely.