{"id":"T1599","name":"Network Boundary Bridging","url":"https://attack.mitre.org/techniques/T1599","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0006","stix_id":"x-mitre-detection-strategy--f0f7aa93-71bc-4c55-9f96-9c74a7d45a83","name":"Detection Strategy for Network Boundary Bridging","url":"https://attack.mitre.org/detectionstrategies/DET0006","analytics":[{"id":"AN0015","stix_id":"x-mitre-analytic--32d56b42-ff83-46d2-aeea-57a6958d3e83","name":"Analytic 0015","description":"From a defender’s perspective, suspicious bridging is observed when network devices begin allowing traffic that contradicts existing segmentation or access policies. Observable behaviors include sudden modifications to ACLs or firewall rules, unusual cross-boundary traffic flows (e.g., east-west communications across separated VLANs), or simultaneous ingress/egress anomalies. Multi-event correlation is key: configuration changes on a router/firewall followed by unexpected traffic patterns, especially from unusual sources, is a strong indicator of compromise.","url":"https://attack.mitre.org/detectionstrategies/DET0006#AN0015","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Unexpected flows between segmented networks or prohibited ports","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"networkdevice:syslog","channel":"ACL/Firewall rule modification or new route injection","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between configuration changes and abnormal traffic; tuned to match expected administrative change cycles."},{"field":"ApprovedChangeList","description":"Known authorized ACL/firewall changes; suppresses noise from legitimate maintenance."},{"field":"GeoLocation","description":"Geographic origin of new traffic patterns; helps distinguish benign remote offices from suspicious foreign access."},{"field":"TrafficVolumeThreshold","description":"Volume of cross-segment traffic; tuned to detect large-scale lateral flows without flagging small test connections."}],"live":true,"detection_strategies":["DET0006"],"techniques":["T1599"]}],"live":true,"version":"1.0","techniques":["T1599"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}