Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1090

T1090Proxy

T1090 — Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 16 detection use cases covering it and 10 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
10Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (16)

Cisco IOS XE Tunnel Interface Configuration ESCU actions · hunting P Okta Non-Standard VPN Usage ESCU actions · alerting P Linux Ngrok Reverse Proxy Usage ESCU actions · hunting P Linux Proxy Socks Curl ESCU actions · alerting P Windows Devtunnels Execution ESCU actions · hunting P Windows Devtunnels Image Loaded ESCU actions · hunting P Windows Ngrok Reverse Proxy Usage ESCU actions · hunting P Ngrok Reverse Proxy on Network ESCU actions · hunting P [LLM] BridgeHead SOCKS5 relay drop: unbcl.dll + libwinpthread-1.dll co-located outside System32 Bespoke c2 · alerting DSΣPDDCS [LLM] BridgeHead WebSocket SOCKS5 tunnel to smartconnect.azurewebsites.net with hardcoded Edg/86 UA Bespoke c2 · alerting DSΣPDDCS [LLM] Dysphoria relay node: public-to-public traffic bridging (UPnP port-forwarding relay) Bespoke c2 · hunting DSPCS [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) Bespoke c2 · hunting DSPDDCS [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru Bespoke c2 · hunting DSΣPDDCS

Articles citing this technique (10)