1200KM / simulation
T1572 Protocol Tunneling — Attack Simulation
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of…
Technique description
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- DNS over HTTPS Regular Beaconing
Procedure 0c5f9705-c575-42a6-9609-cbbff4b2fc9b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Cloudflare tunnels (Linux/macOS)
Procedure 228c336a-2f79-4043-8aef-bfa453a611d5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Install and Run gost Tunnel Proxy
Procedure 3afc90c4-90b3-44af-8d14-52852abe7258; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- run ngrok
Procedure 4cdc9fc7-53fb-4894-9f0c-64836943ea60; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- DNS over HTTPS Long Domain Query
Procedure 748a73d5-cea4-4f34-84d8-839da5baa99c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Microsoft Dev tunnels (Linux/macOS)
Procedure 9f94a112-1ce2-464d-a63b-83c1f465f801; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- DNS over HTTPS Large Query Volume
Procedure ae9ef4b0-d8c1-49d4-8758-06206f19af0a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- VSCode tunnels (Linux/macOS)
Procedure b877943f-0377-44f4-8477-f79db7f07c4d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Install and Run frpc Reverse Proxy Client
Procedure f54179ee-c782-4fe3-b836-213d3bda66a2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.