1200KM / detection
T1090 Proxy — Detection Rules
Detection workspace for T1090 Proxy: 21 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - HTTPPROXY Login Attempt · test · high · {"category":"application","product":"opencanary"}
- Malicious IP Address Sign-In Failure Rate · test · high · {"product":"azure","service":"riskdetection"}
- Malicious IP Address Sign-In Suspicious · test · high · {"product":"azure","service":"riskdetection"}
- Sign-In From Malware Infected IP · test · high · {"product":"azure","service":"riskdetection"}
- Communication To LocaltoNet Tunneling Service Initiated - Linux · test · high · {"category":"network_connection","product":"linux"}
- Communication To Ngrok Tunneling Service - Linux · test · high · {"product":"linux","category":"network_connection"}
- Connection Proxy · test · low · {"product":"linux","category":"process_creation"}
- Ngrok Usage with Remote Desktop Service · test · high · {"product":"windows","service":"terminalservices-localsessionmanager"}
- Communication To LocaltoNet Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Communication To Ngrok Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Suspicious TCP Tunnel Via PowerShell Script · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Cloudflared Tunnel Connections Cleanup · test · medium · {"category":"process_creation","product":"windows"}
- Cloudflared Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- HackTool - Htran/NATBypass Execution · test · high · {"category":"process_creation","product":"windows"}
- New Port Forwarding Rule Added Via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- RDP Port Forwarding Rule Added Via Netsh.EXE · test · high · {"category":"process_creation","product":"windows"}
- PUA - Fast Reverse Proxy (FRP) Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA- IOX Tunneling Tool Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - NPS Tunneling Tool Execution · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Usage Of Qemu · test · medium · {"category":"process_creation","product":"windows"}
- New PortProxy Registry Entry Added · test · medium · {"category":"registry_event","product":"windows"}
Atlas deterministic concepts
T1090 Proxy
MATCH(proxy_or_tunnel_process_or_configuration) AND actor_or_binary NOT_IN approved_proxy_tools -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0445 Detection of Proxy Infrastructure Setup and Traffic Bridging
AN1229 Analytic 1229
Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.
AN1230 Analytic 1230
User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.
AN1231 Analytic 1231
AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.
AN1232 Analytic 1232
Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.
AN1233 Analytic 1233
Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Sandworm Team · G0034
- Gamaredon Group · G0047
- CopyKittens · G0052
- Magic Hound · G0059
- MuddyWater · G0069
- APT41 · G0096
- Blue Mockingbird · G0108
- Fox Kitten · G0117
- Windigo · G0124
- LAPSUS$ · G1004
- POLONIUM · G1005
- Earth Lusca · G1006
- Scattered Spider · G1015
- Volt Typhoon · G1017
- MoustachedBouncer · G1019
- Cinnamon Tempest · G1021
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.