Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?
Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.