{"id":"T1090","name":"Proxy","url":"https://attack.mitre.org/techniques/T1090","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0445","stix_id":"x-mitre-detection-strategy--5c44619a-da36-4bbd-9730-efceacf2409f","name":"Detection of Proxy Infrastructure Setup and Traffic Bridging","url":"https://attack.mitre.org/detectionstrategies/DET0445","analytics":[{"id":"AN1229","stix_id":"x-mitre-analytic--0e9add05-93bd-47b2-acf5-1817f03e804a","name":"Analytic 1229","description":"Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.","url":"https://attack.mitre.org/detectionstrategies/DET0445#AN1229","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Connections","channel":"Outbound Connection","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"ParentProcessName","description":"Legitimate system processes that may rarely spawn network-capable child processes (e.g., `rundll32`, `svchost`)."},{"field":"DestinationPort","description":"Watch for high-numbered ports or well-known proxy ports like 1080, 8080, 4444."},{"field":"TimeWindow","description":"Capture unusual spikes in outbound connections over a short period."}],"live":true,"detection_strategies":["DET0445"],"techniques":["T1090"]},{"id":"AN1230","stix_id":"x-mitre-analytic--b95a3fbf-3d6c-4ead-8421-ff9c07ca4019","name":"Analytic 1230","description":"User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.","url":"https://attack.mitre.org/detectionstrategies/DET0445#AN1230","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Connection Tracking","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Shell piping into tools like `socat`, `ncat`, or `openssl` for tunnel creation."},{"field":"OutboundPortRange","description":"Flag connections made from internal systems to uncommon high ports externally."},{"field":"ProcessUserContext","description":"Capture low-privilege or unexpected users executing system-level network tools."}],"live":true,"detection_strategies":["DET0445"],"techniques":["T1090"]},{"id":"AN1231","stix_id":"x-mitre-analytic--aace8c0e-4534-432b-9a84-6e01c19570b7","name":"Analytic 1231","description":"AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.","url":"https://attack.mitre.org/detectionstrategies/DET0445#AN1231","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"None","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Firewall","channel":"pf firewall logs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-firewall"},{"name":"NSM:Flow","channel":"connection attempts","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TargetDomain","description":"Identify suspicious domains often associated with CDN-routed or anonymized endpoints (e.g., Cloudflare, Fastly)."},{"field":"AppleScriptUsage","description":"Alert when AppleScript or Automator tools are used for network tunneling tasks."},{"field":"LaunchAgentSource","description":"Monitor for LaunchAgents executing proxy tools or dynamic ports."}],"live":true,"detection_strategies":["DET0445"],"techniques":["T1090"]},{"id":"AN1232","stix_id":"x-mitre-analytic--d8cc8663-020b-4fde-a8de-a92ecf97aea4","name":"Analytic 1232","description":"Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.","url":"https://attack.mitre.org/detectionstrategies/DET0445#AN1232","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"esxi:vmkernel","channel":"None","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vmkernel"},{"name":"NSM:Flow","channel":"conn.log","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"CLICommand","description":"Custom proxy or port forwarding scripts executed from ESXi shell."},{"field":"DestinationIP","description":"Unusual outbound connections from ESXi host, particularly to internet."},{"field":"UserContext","description":"Root or elevated users initiating unexpected tunnels."}],"live":true,"detection_strategies":["DET0445"],"techniques":["T1090"]},{"id":"AN1233","stix_id":"x-mitre-analytic--a79ae1d1-1a8d-427d-aa6d-261ea63d5650","name":"Analytic 1233","description":"Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.","url":"https://attack.mitre.org/detectionstrategies/DET0445#AN1233","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Firewall","channel":"Policy Change / Rule Update","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"nsm-firewall"},{"name":"NSM:Flow","channel":"Flow Creation (NetFlow/sFlow)","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"networkdevice:cli","channel":"Interface commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"RuleType","description":"Focus on new allow/permit rules with dynamic NAT or port forwarders."},{"field":"ChangeUser","description":"Flag any non-admins initiating proxy config changes."},{"field":"FlowVolumeDelta","description":"Detect sharp changes in bi-directional traffic patterns."}],"live":true,"detection_strategies":["DET0445"],"techniques":["T1090"]}],"live":true,"version":"1.0","techniques":["T1090"]}],"sigma_rules":[{"id":"19bf6fdb-7721-4f3d-867f-53467f6a5db6","title":"Communication To Ngrok Tunneling Service - Linux","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":null,"description":"Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/linux/network_connection/net_connection_lnx_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"1d08ac94-400d-4469-a82f-daee9a908849","title":"Communication To Ngrok Tunneling Service Initiated","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":"2024-02-02","description":"Detects an executable initiating a network connection to \"ngrok\" tunneling domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"322ed9ec-fcab-4f67-9a34-e7c6aef43614","title":"New Port Forwarding Rule Added Via Netsh.EXE","author":"Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel","status":"test","level":"medium","date":"2019-01-29","modified":"2023-09-01","description":"Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule","references":["https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html","https://adepts.of0x.cc/netsh-portproxy-code/","https://www.dfirnotes.net/portproxy_detection/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.command-and-control","attack.t1090"],"path":"rules/windows/process_creation/proc_creation_win_netsh_port_forwarding.yml","techniques":["T1090"],"cves":[]},{"id":"32410e29-5f94-4568-b6a3-d91a8adad863","title":"PUA - Fast Reverse Proxy (FRP) Execution","author":"frack113, Florian Roth","status":"test","level":"high","date":"2022-09-02","modified":"2024-11-23","description":"Detects the use of Fast Reverse Proxy. frp is a fast reverse proxy to help you expose a local server behind a NAT or firewall to the Internet.","references":["https://asec.ahnlab.com/en/38156/","https://github.com/fatedier/frp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/windows/process_creation/proc_creation_win_pua_frp.yml","techniques":["T1090"],"cves":[]},{"id":"36440e1c-5c22-467a-889b-593e66498472","title":"Malicious IP Address Sign-In Suspicious","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-07","modified":null,"description":"Indicates sign-in from a malicious IP address known to be malicious at time of sign-in.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#malicious-ip-address","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1090","attack.command-and-control"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_malicious_ip_address_suspicious.yml","techniques":["T1090"],"cves":[]},{"id":"3ab65069-d82a-4d44-a759-466661a082d1","title":"Communication To LocaltoNet Tunneling Service Initiated","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"5498fc09-adc6-4804-b9d9-5cca1f0b8760","title":"OpenCanary - HTTPPROXY Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an HTTPPROXY service on an OpenCanary node has had an attempt to proxy another page.\n","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.initial-access","attack.command-and-control","attack.t1090"],"path":"rules/application/opencanary/opencanary_httpproxy_login_attempt.yml","techniques":["T1090"],"cves":[]},{"id":"5fc297ae-25b6-488a-8f25-cc12ac29b744","title":"Potentially Suspicious Usage Of Qemu","author":"Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR)","status":"test","level":"medium","date":"2024-06-03","modified":null,"description":"Detects potentially suspicious execution of the Qemu utility in a Windows environment.\nThreat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.\n","references":["https://securelist.com/network-tunneling-with-qemu/111803/","https://www.qemu.org/docs/master/system/invocation.html#hxtool-5"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_qemu_suspicious_execution.yml","techniques":["T1090","T1572"],"cves":[]},{"id":"64d51a51-32a6-49f0-9f3d-17e34d640272","title":"Ngrok Usage with Remote Desktop Service","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-29","modified":null,"description":"Detects cases in which ngrok, a reverse proxy tool, forwards events to the local RDP port, which could be a sign of malicious behaviour","references":["https://twitter.com/tekdefense/status/1519711183162556416?s=12&t=OTsHCBkQOTNs1k3USz65Zg","https://ngrok.com/"],"logsource":{"product":"windows","service":"terminalservices-localsessionmanager"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/windows/builtin/terminalservices/win_terminalservices_rdp_ngrok.yml","techniques":["T1090"],"cves":[]},{"id":"68d37776-61db-42f5-bf54-27e87072d17e","title":"PUA - NPS Tunneling Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-10-08","modified":"2024-11-23","description":"Detects the use of NPS, a port forwarding and intranet penetration proxy server","references":["https://github.com/ehang-io/nps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/windows/process_creation/proc_creation_win_pua_nps.yml","techniques":["T1090"],"cves":[]},{"id":"7050bba1-1aed-454e-8f73-3f46f09ce56a","title":"Cloudflared Tunnel Connections Cleanup","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-21","description":"Detects execution of the \"cloudflared\" tool with the tunnel \"cleanup\" flag in order to cleanup tunnel connections.","references":["https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_cleanup.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"72f4ab3f-787d-495d-a55d-68c2ff46cf4c","title":"Connection Proxy","author":"Ömer Günal","status":"test","level":"low","date":"2020-06-17","modified":"2022-10-05","description":"Detects setting proxy configuration","references":[],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/linux/process_creation/proc_creation_lnx_proxy_connection.yml","techniques":["T1090"],"cves":[]},{"id":"782d6f3e-4c5d-4b8c-92a3-1d05fed72e63","title":"RDP Port Forwarding Rule Added Via Netsh.EXE","author":"Florian Roth (Nextron Systems), oscd.community","status":"test","level":"high","date":"2019-01-29","modified":"2023-02-13","description":"Detects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule","references":["https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.command-and-control","attack.t1090"],"path":"rules/windows/process_creation/proc_creation_win_netsh_port_forwarding_3389.yml","techniques":["T1090"],"cves":[]},{"id":"821b4dc3-1295-41e7-b157-39ab212dd6bd","title":"Sign-In From Malware Infected IP","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Indicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#malware-linked-ip-address-deprecated","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1090","attack.command-and-control"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_malware_linked_ip.yml","techniques":["T1090"],"cves":[]},{"id":"9a019ffc-3580-4c9d-8d87-079f7e8d3fd4","title":"Cloudflared Tunnel Execution","author":"Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-20","description":"Detects execution of the \"cloudflared\" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.","references":["https://blog.reconinfosec.com/emergence-of-akira-ransomware-group","https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_run.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"a3f55ebd-0c01-4ed6-adc0-8fb76d8cd3cd","title":"Malicious IP Address Sign-In Failure Rate","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-07","modified":null,"description":"Indicates sign-in from a malicious IP address based on high failure rates.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#malicious-ip-address","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1090","attack.command-and-control"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_malicious_ip_address.yml","techniques":["T1090"],"cves":[]},{"id":"a54f842a-3713-4b45-8c84-5f136fdebd3c","title":"New PortProxy Registry Entry Added","author":"Andreas Hunkeler (@Karneades)","status":"test","level":"medium","date":"2021-06-22","modified":"2024-03-25","description":"Detects the modification of the PortProxy registry key which is used for port forwarding.","references":["https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html","https://adepts.of0x.cc/netsh-portproxy-code/","https://www.dfirnotes.net/portproxy_detection/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.lateral-movement","attack.command-and-control","attack.t1090"],"path":"rules/windows/registry/registry_event/registry_event_portproxy_registry_key.yml","techniques":["T1090"],"cves":[]},{"id":"bd33d2aa-497e-4651-9893-5c5364646595","title":"Suspicious TCP Tunnel Via PowerShell Script","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-08","modified":null,"description":"Detects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity","references":["https://github.com/Arno0x/PowerShellScripts/blob/a6b7d5490fbf0b20f91195838f3a11156724b4f7/proxyTunnel.ps1"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_proxy_scripts.yml","techniques":["T1090"],"cves":[]},{"id":"c4568f5d-131f-4e78-83d4-45b2da0ec4f1","title":"Communication To LocaltoNet Tunneling Service Initiated - Linux","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/linux/network_connection/net_connection_lnx_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"d7654f02-e04b-4934-9838-65c46f187ebc","title":"PUA- IOX Tunneling Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-10-08","modified":"2024-11-23","description":"Detects the use of IOX - a tool for port forwarding and intranet proxy purposes","references":["https://github.com/EddieIvan01/iox"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090"],"path":"rules/windows/process_creation/proc_creation_win_pua_iox.yml","techniques":["T1090"],"cves":[]},{"id":"e99375eb-3ee0-407a-9f90-79569cc6a01c","title":"Kalambur Backdoor Curl TOR SOCKS Proxy Execution","author":"Arda Buyukkaya (EclecticIQ)","status":"experimental","level":"high","date":"2025-02-11","modified":null,"description":"Detects the execution of the \"curl.exe\" command, referencing \"SOCKS\" and \".onion\" domains, which could be indicative of Kalambur backdoor activity.","references":["https://blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-with-trojanized-microsoft-kms-activation-tools-in-cyber-espionage-campaigns"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.t1090","attack.t1573","attack.t1071.001","attack.t1059.001","attack.s0183","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/proc_creation_win_malware_kalambur_curl_socks_tor.yml","techniques":["T1090","T1573","T1071.001","T1059.001"],"cves":[]},{"id":"f5e3b62f-e577-4e59-931e-0a15b2b94e1e","title":"HackTool - Htran/NATBypass Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-12-27","modified":"2023-02-04","description":"Detects executable names or flags used by Htran or Htran-like tools (e.g. NATBypass)","references":["https://github.com/HiwinCN/HTran","https://github.com/cw1997/NATBypass"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090","attack.s0040"],"path":"rules/windows/process_creation/proc_creation_win_hktl_htran_or_natbypass.yml","techniques":["T1090"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2019-3396","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-22986","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-26855","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}