For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual Netsh PortProxy rule

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

LOLBIN Execution Analytics

ATT&CK Tactic

Command and Control (TA0011), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify System Firewall (T1686), Proxy: Internal Proxy (T1090.001)

Severity

Low

Description

Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).

Attacker's Goals

Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.

Investigative actions

  • Check the connect address and if it's a known IP/domain.

  • Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.

Variations

Unusual Netsh PortProxy rule by non-netsh process

Synopsis

Field
Value

ATT&CK Tactic

Command and Control (TA0011), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify System Firewall (T1686), Proxy: Internal Proxy (T1090.001)

Severity

Medium

Description

Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).

Attacker's Goals

Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.

Investigative actions

  • Check the connect address and if it's a known IP/domain.

  • Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.

Unusual Netsh PortProxy rule by an unsigned causality actor

Synopsis

Field
Value

ATT&CK Tactic

Command and Control (TA0011), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify System Firewall (T1686), Proxy: Internal Proxy (T1090.001)

Severity

Medium

Description

Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).

Attacker's Goals

Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.

Investigative actions

  • Check the connect address and if it's a known IP/domain.

  • Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.

Was this helpful?