How spoofing an Ethernet adaptor lets you sniff PC credentials

I think some of you have already read about this. But I don’t understand if this attack works only if User has locked his pc or for standard logon procedure as well… (first login)

Thank you in advance.