A MAC address change doesn't necessarily mean a MITM.
For example, if you visit many Starbucks locations, you'll see different MAC addresses for each location, but they all have the same SSID.
The MITM detection in SandBlast can be configured by dashboard admin and is related to checking HTTPS traffic.
To edit the settings click on Settings -> Policy Settings ->WIFI Network
- SSL Striping - MITM attack - intercepts all network traffic redirection from HTTP to HTTPS and "strips" the HTTPS call leaving the traffic as HTTP.
- SSL Interception (Basic) - MITM attack - intercepts HTTPS traffic by using an invalid certificate that does not exist on the device's trusted certificates or not trusted by a root CA.
- SSL Interception (Advanced) - MITM attack - intercepts HTTPS traffic by using a valid certificate that does not match the certificate of the server.
You can also configure the specific HTTPS URLs that can be checked as well.