home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

networkThreatDetails:arpSpoofDetails Fields

Man-in-the-Middle ARP spoof events are returned as THREAT events with type=NETWORK and a networkThreatDetails:arpSpoofDetails block with the following information:

"details": {
  ...,
  "assessments": [...],
  "networkThreatDetails": {
    "arpSpoofDetails" {
      "type": "ARP_SPOOF"
    }
  }
}
Field Type Description
type
String Always ARP_SPOOF