Analytics BIOC Low

Unusual Netsh PortProxy rule

Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Command and Control (TA0011)
ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004) Proxy: Internal Proxy (T1090.001)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.

Investigative actions:

Check the connect address and if it's a known IP/domain. Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Unusual Netsh PortProxy rule by non-netsh process Medium (parent: Low)
  • Unusual Netsh PortProxy rule by an unsigned causality actor Medium (parent: Low)