Cross-source coverage

T1188 / ATT&CK

Multi-hop Proxy

ATT&CK has retired this technique. Rules still tag it; the current id is T1090.003 Proxy: Multi-hop Proxy.

1 rule across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

To disguise the source of malicious traffic, adversaries may chain together multiple proxies. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

1 rule
Detection Severity Format
suspicious_curl_usage Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.