1200KM / detection
T1090.001 Internal Proxy — Detection Rules
Detection workspace for T1090.001 Internal Proxy: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- RDP over Reverse SSH Tunnel WFP · test · high · {"product":"windows","service":"security"}
- Cloudflared Portable Execution · test · medium · {"category":"process_creation","product":"windows"}
- Cloudflared Quick Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- HackTool - SharpChisel Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Chisel Tunneling Tool Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed Cloudflared.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0075 Internal Proxy Behavior via Lateral Host-to-Host C2 Relay
AN0204 Analytic 0204
Anomalous process (e.g., `rundll32`, `svchost`, `cmd`) initiates connections to internal peer hosts not seen in typical communication baselines, used to proxy or forward traffic internally, often using SMB, RPC, or high ports.
AN0205 Analytic 0205
`socat`, `ssh`, `iptables`, or `ncat` invoked from user space or cron jobs to create port forwarding, reverse shells, or inter-host tunnels between compromised Linux systems. Behavior is typically paired with socket activity and high entropy traffic.
AN0206 Analytic 0206
Execution of AppleScript or Automator services launching `ssh -L`, `socat`, or `launchctl` items that dynamically reroute traffic from one Mac endpoint to another. LaunchAgents used to establish permanent internal tunnels.
AN0207 Analytic 0207
ESXi shell execution of tools/scripts (`nc`, `socat`, `perl`) relaying network traffic to other internal hosts, especially when initiated by unauthorized users or VMs.
AN0208 Analytic 0208
Configuration of internal NAT or proxy rules that redirect traffic between client segments internally (e.g., site-to-site port forwarding). Often used to relay internal beaconing or move traffic laterally through trust zones.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.