Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1090.001

T1090.001Internal Proxy

T1090.001 — Internal Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 8 detection use cases covering it and 6 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (8)

Windows Proxy Via Netsh ESCU actions · hunting P Windows Proxy Via Registry ESCU actions · hunting P [LLM] Dysphoria relay node: public-to-public traffic bridging (UPnP port-forwarding relay) Bespoke c2 · hunting DSPCS [LLM] msaRAT: Connection to Chaos delivery IP / workers.dev signaling relay Bespoke c2 · hunting DSΣPDDCS [LLM] HelloProxy listener: svchost.exe binding TCP 5003/5060 Bespoke c2 · alerting DSP [LLM] GoSerpent/McMx masquerading proxy binaries lass.exe and updates.exe Bespoke install · alerting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP

Articles citing this technique (6)