Cross-source coverage
T1090 / ATT&CK
Proxy
99 rules across 9 sources.
Showing deprecated and atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SysmonNSM:Connectionsauditd:SYSCALLNSM:Flowmacos:unifiedlogNSM:Firewallesxi:shellesxi:vmkernelnetworkdevice:cli
How MITRE says to detect it DET0445
Detection of Proxy Infrastructure Setup and Traffic Bridging
Windows Analytic 1229
Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.
WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=1NSM:ConnectionsOutbound Connection
Linux Analytic 1230
User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.
auditd:SYSCALLexecveNSM:FlowConnection Tracking
macOS Analytic 1231
AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.
macos:unifiedlogNoneNSM:Firewallpf firewall logsNSM:Flowconnection attempts
ESXi Analytic 1232
Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.
esxi:shellNoneesxi:vmkernelNoneNSM:Flowconn.log
Network Devices Analytic 1233
Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.
NSM:FirewallPolicy Change / Rule UpdateNSM:FlowFlow Creation (NetFlow/sFlow)networkdevice:cliInterface commands
Sub-techniques with coverage
Counted in the 99 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
33 rules| Detection | Severity | Format |
|---|---|---|
| Communication To LocaltoNet Tunneling Service Initiated | High | Sigma |
| Communication To LocaltoNet Tunneling Service Initiated - Linux | High | Sigma |
| Communication To Ngrok Tunneling Service Initiated | High | Sigma |
| Communication To Ngrok Tunneling Service - Linux | High | Sigma |
| DNS Query Tor .Onion Address - Sysmon | High | Sigma |
| HackTool - Htran/NATBypass Execution | High | Sigma |
| HackTool - SharpChisel Execution | High | Sigma |
| Kalambur Backdoor Curl TOR SOCKS Proxy Execution | High | Sigma |
| Malicious IP Address Sign-In Failure Rate | High | Sigma |
| Malicious IP Address Sign-In Suspicious | High | Sigma |
+ 23 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
22 rules| Detection | Severity | Format |
|---|---|---|
| Potential Protocol Tunneling via EarthWorm | High | Elastic TOML |
| Curl SOCKS Proxy Activity from Unusual Parent | Medium | Elastic TOML |
| Curl SOCKS Proxy Detected via Defend for Containers | Medium | Elastic TOML |
| FortiGate SOCKS Traffic from an Unusual Process | Medium | Elastic TOML |
| Port Forwarding Rule Addition | Medium | Elastic TOML |
| Potential Linux Tunneling and/or Port Forwarding | Medium | Elastic TOML |
| Potential Linux Tunneling and/or Port Forwarding via Command Line | Medium | Elastic TOML |
| Potential Protocol Tunneling via Chisel Client | Medium | Elastic TOML |
| Potential Protocol Tunneling via Cloudflared | Medium | Elastic TOML |
| Potential Protocol Tunneling via Yuze | Medium | Elastic TOML |
+ 12 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
14 rules| Detection | Severity | Format |
|---|---|---|
| Cisco IOS XE Tunnel Interface Configuration | Undefined | SPL |
| Cisco SA - Access to Anonymizer Services | Undefined | SPL |
| Cisco Secure Firewall - Connection to File Sharing Domain | Undefined | SPL |
| Linux Ngrok Reverse Proxy Usage | Undefined | SPL |
| Linux Proxy Socks Curl | Undefined | SPL |
| Ngrok Reverse Proxy on Network | Undefined | SPL |
| Okta Non-Standard VPN Usage | Undefined | SPL |
| TOR Traffic | Undefined | SPL |
| Windows Devtunnels Execution | Undefined | SPL |
| Windows Devtunnels Image Loaded | Undefined | SPL |
+ 4 more from splunk/security_content → showing the 10 highest-severity
Emerging Threats Open
10 rules| Detection | Severity | Format |
|---|---|---|
| ET MALWARE EARTHWORM SOCKS Proxy Tunnel Post Setup Request | High | Suricata |
| ET MALWARE EARTHWORM SOCKS Proxy Tunnel Response | High | Suricata |
| ET MALWARE EARTHWORM SOCKS Reverse Proxy Assign Pool Number Request | High | Suricata |
| ET MALWARE EARTHWORM SOCKS Reverse Proxy Initial Setup Request | High | Suricata |
| ET MALWARE EARTHWORM SOCKS Reverse Proxy Server Response | High | Suricata |
| ET MALWARE EARTHWORM SOCKS Reverse Proxy Tunnel Request | High | Suricata |
| ET MALWARE HTran/SensLiceld.A response to infected host - Inbound Connection Attempt | High | Suricata |
| ET MALWARE HTran/SensLiceld.A response to infected host - Outbound Connection Attempt | High | Suricata |
| ET MALWARE upStage Proxy Heartbeat | High | Suricata |
| ET MALWARE Win32/ElectricFish Authentication Packet Observed | High | Suricata |
chronicle/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| google_safebrowsing_file_contacts_tor_exit_node | Critical | YARA-L |
| vt_relationships_file_contacts_tor_ip | Critical | YARA-L |
| aws_guardduty_tor_network_activity_detected | High | YARA-L |
| gcti_benign_binaries_contacts_tor_exit_node | High | YARA-L |
| gcti_tor_exit_nodes | High | YARA-L |
| port_proxy_forwarding_T1090_cisa_report | Low | YARA-L |
| north_korean_tunneling_tool__electricfish_detection_ar19129a | Undefined | YARA-L |
socfortress/Wazuh-Rules
7 rules| Detection | Severity | Format |
|---|---|---|
| Possible proxy usage with curl detected (MITRE T1090.001) | High | Wazuh XML |
| Proxy environment variable set — possible redirection attempt (T1090.001) | High | Wazuh XML |
| Sysmon - Event 13: RegistryEvent (Value Set) by · PortProxy Registry Modification (T1090.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PortProxy Setup via Netsh (T1090.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Psiphon Proxy (T1090.003) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Tor Proxy Usage (T1090.003) | High | Wazuh XML |
| Tor proxy service start detected (potential anonymizing proxy usage) | High | Wazuh XML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Hunt for the events that have been performed while connected to a Anonymous Proxy | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| Squid: Multiple unauthorized attempts to use proxy. | High | Wazuh XML |
| authorized to use proxy. | Low | Wazuh XML |
panther-labs/panther-analysis
2 rules| Detection | Severity | Format |
|---|---|---|
| AppOmni Alert Passthrough | Medium | Panther Python |
| AWS WAF Managed IP Reputation Passthrough Rule | Informational | Panther Python |