T1090.001Internal Proxy
T1090.001 — Internal Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 8 detection use cases covering it and 6 threat-intel articles citing it.
Command and Control
8Use cases
6Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1090 · Proxy
Use cases covering this technique (8)
Windows Proxy Via Netsh Windows Proxy Via Registry [LLM] Dysphoria relay node: public-to-public traffic bridging (UPnP port-forwarding relay) [LLM] msaRAT: Connection to Chaos delivery IP / workers.dev signaling relay [LLM] HelloProxy listener: svchost.exe binding TCP 5003/5060 [LLM] GoSerpent/McMx masquerading proxy binaries lass.exe and updates.exe [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2)Articles citing this technique (6)
crit Don’t swing at everything art-106