Cross-source coverage

T1090 / ATT&CK

Proxy

96 rules across 9 sources.

3 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.

Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SysmonNSM:Connectionsauditd:SYSCALLNSM:Flowmacos:unifiedlogNSM:Firewallesxi:shellesxi:vmkernelnetworkdevice:cli

How MITRE says to detect it DET0445

Detection of Proxy Infrastructure Setup and Traffic Bridging

Windows Analytic 1229

Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.

  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=1
  • NSM:Connections Outbound Connection

Linux Analytic 1230

User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.

  • auditd:SYSCALL execve
  • NSM:Flow Connection Tracking

macOS Analytic 1231

AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.

  • macos:unifiedlog None
  • NSM:Firewall pf firewall logs
  • NSM:Flow connection attempts

ESXi Analytic 1232

Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.

  • esxi:shell None
  • esxi:vmkernel None
  • NSM:Flow conn.log

Network Devices Analytic 1233

Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.

  • NSM:Firewall Policy Change / Rule Update
  • NSM:Flow Flow Creation (NetFlow/sFlow)
  • networkdevice:cli Interface commands

Sub-techniques with coverage

Counted in the 96 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

30 rules
Detection Severity Format
Communication To LocaltoNet Tunneling Service Initiated High Sigma
Communication To LocaltoNet Tunneling Service Initiated - Linux High Sigma
HackTool - Htran/NATBypass Execution High Sigma
HackTool - SharpChisel Execution High Sigma
Kalambur Backdoor Curl TOR SOCKS Proxy Execution High Sigma
Malicious IP Address Sign-In Failure Rate High Sigma
Malicious IP Address Sign-In Suspicious High Sigma
Ngrok Usage with Remote Desktop Service High Sigma
OpenCanary - HTTPPROXY Login Attempt High Sigma
PUA - Chisel Tunneling Tool Execution High Sigma

+ 20 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

22 rules
Detection Severity Format
Potential Protocol Tunneling via EarthWorm High Elastic TOML
Curl SOCKS Proxy Activity from Unusual Parent Medium Elastic TOML
Curl SOCKS Proxy Detected via Defend for Containers Medium Elastic TOML
FortiGate SOCKS Traffic from an Unusual Process Medium Elastic TOML
Port Forwarding Rule Addition Medium Elastic TOML
Potential Linux Tunneling and/or Port Forwarding Medium Elastic TOML
Potential Linux Tunneling and/or Port Forwarding via Command Line Medium Elastic TOML
Potential Protocol Tunneling via Chisel Client Medium Elastic TOML
Potential Protocol Tunneling via Cloudflared Medium Elastic TOML
Potential Protocol Tunneling via Yuze Medium Elastic TOML

+ 12 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

14 rules
Detection Severity Format
Cisco IOS XE Tunnel Interface Configuration Undefined SPL
Cisco SA - Access to Anonymizer Services Undefined SPL
Cisco Secure Firewall - Connection to File Sharing Domain Undefined SPL
Linux Ngrok Reverse Proxy Usage Undefined SPL
Linux Proxy Socks Curl Undefined SPL
Ngrok Reverse Proxy on Network Undefined SPL
Okta Non-Standard VPN Usage Undefined SPL
TOR Traffic Undefined SPL
Windows Devtunnels Execution Undefined SPL
Windows Devtunnels Image Loaded Undefined SPL

+ 4 more from splunk/security_content → showing the 10 highest-severity

Emerging Threats Open

10 rules
Detection Severity Format
ET MALWARE EARTHWORM SOCKS Proxy Tunnel Post Setup Request High Suricata
ET MALWARE EARTHWORM SOCKS Proxy Tunnel Response High Suricata
ET MALWARE EARTHWORM SOCKS Reverse Proxy Assign Pool Number Request High Suricata
ET MALWARE EARTHWORM SOCKS Reverse Proxy Initial Setup Request High Suricata
ET MALWARE EARTHWORM SOCKS Reverse Proxy Server Response High Suricata
ET MALWARE EARTHWORM SOCKS Reverse Proxy Tunnel Request High Suricata
ET MALWARE HTran/SensLiceld.A response to infected host - Inbound Connection Attempt High Suricata
ET MALWARE HTran/SensLiceld.A response to infected host - Outbound Connection Attempt High Suricata
ET MALWARE upStage Proxy Heartbeat High Suricata
ET MALWARE Win32/ElectricFish Authentication Packet Observed High Suricata

chronicle/detection-rules

7 rules
Detection Severity Format
google_safebrowsing_file_contacts_tor_exit_node Critical YARA-L
vt_relationships_file_contacts_tor_ip Critical YARA-L
aws_guardduty_tor_network_activity_detected High YARA-L
gcti_benign_binaries_contacts_tor_exit_node High YARA-L
gcti_tor_exit_nodes High YARA-L
port_proxy_forwarding_T1090_cisa_report Low YARA-L
north_korean_tunneling_tool__electricfish_detection_ar19129a Undefined YARA-L

socfortress/Wazuh-Rules

7 rules
Detection Severity Format
Possible proxy usage with curl detected (MITRE T1090.001) High Wazuh XML
Proxy environment variable set — possible redirection attempt (T1090.001) High Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · PortProxy Registry Modification (T1090.001) High Wazuh XML
Sysmon - Event 1: Process creation · PortProxy Setup via Netsh (T1090.001) High Wazuh XML
Sysmon - Event 1: Process creation · Psiphon Proxy (T1090.003) High Wazuh XML
Sysmon - Event 1: Process creation · Tor Proxy Usage (T1090.003) High Wazuh XML
Tor proxy service start detected (potential anonymizing proxy usage) High Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Hunt for the events that have been performed while connected to a Anonymous Proxy Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
Squid: Multiple unauthorized attempts to use proxy. High Wazuh XML
authorized to use proxy. Low Wazuh XML

panther-labs/panther-analysis

2 rules
Detection Severity Format
AppOmni Alert Passthrough Medium Panther Python
AWS WAF Managed IP Reputation Passthrough Rule Informational Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.