Unusual Netsh PortProxy rule
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Command and Control (TA0011), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify System Firewall (T1686), Proxy: Internal Proxy (T1090.001)
Severity
Low
Description
Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).
Attacker's Goals
Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.
Investigative actions
Check the connect address and if it's a known IP/domain.
Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.
Variations
Was this helpful?
