Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1090.001

T1090.001Internal Proxy

T1090.001 — Internal Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 6 detection use cases covering it and 4 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Windows Proxy Via Netsh ESCU actions · hunting P Windows Proxy Via Registry ESCU actions · hunting P [LLM] Internet-facing web service spawning interactive SSH into management subnet Bespoke delivery · alerting DSΣPDDCS [LLM] OpenSSH reverse port-forward (-R) launched on a workstation - Cloud Atlas backup C2 Bespoke c2 · alerting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP

Articles citing this technique (4)