Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1090.002

T1090.002External Proxy

T1090.002 — External Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 6 detection use cases covering it and 5 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Cisco Secure Firewall - Connection to File Sharing Domain ESCU actions · hunting P [LLM] Browser egress to Myxa SOCKS5 proxy infrastructure (known IPs) Bespoke c2 · hunting DSΣPDDCS [LLM] DNS/connection to Myxa fake-VPN impersonation domains Bespoke c2 · alerting DSΣPDDCS [LLM] Browser-initiated SOCKS5 to TCP/1082 — new proxy infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] SectopRAT in-browser proxy /churl traffic mirroring to attacker IPs Bespoke c2 · hunting DSΣPDDCS [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP

Articles citing this technique (5)