1200KM / tool
FRP — Attack Tool
FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet. FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: FRP
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Magic Hound · G0059 · Pinned relationship source (relationship--6372dcb7-0f8e-45cd-a1a6-5a2cfc4c22ee)
- Blue Mockingbird · G0108 · Pinned relationship source (relationship--0ceaba74-3ead-4070-bbe6-68912552d98c)
- Volt Typhoon · G1017 · Pinned relationship source (relationship--e6bec88c-2706-404a-aca0-50036169d64f)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- Firewall Rule Modification · DC0051
- Firmware Modification · DC0004
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Creation · DC0032
- Script Execution · DC0029
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.