Analytics BIOC
Low
✕
Unusual Netsh PortProxy rule
Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling).
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Command and Control (TA0011)
ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004) Proxy: Internal Proxy (T1090.001)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Adding or deleting netsh forwarding rules as a proxy and to avoid possible detection.
Investigative actions:
Check the connect address and if it's a known IP/domain. Check whether the causality group owner (CGO) process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Unusual Netsh PortProxy rule by non-netsh process Medium (parent: Low)
- Unusual Netsh PortProxy rule by an unsigned causality actor Medium (parent: Low)