Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1572

T1572Protocol Tunneling

T1572 — Protocol Tunneling is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 27 detection use cases covering it and 14 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
27Use cases
14Articles
0Sub-techniques
1Tactic

Use cases covering this technique (27)

[WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD Cisco IOS XE Tunnel Interface Configuration ESCU actions · hunting P Okta Non-Standard VPN Usage ESCU actions · alerting P Linux Ngrok Reverse Proxy Usage ESCU actions · hunting P Windows Ngrok Reverse Proxy Usage ESCU actions · hunting P Windows Potential Cloudflared Network Connection ESCU actions · hunting P Windows Potential Cloudflared Tunnel Execution ESCU actions · hunting P Windows Protocol Tunneling with Plink ESCU actions · alerting P Windows SoftEther VPN Masquerading as Legitimate Binary ESCU actions · alerting P Windows SSH Proxy Command ESCU actions · hunting P Ngrok Reverse Proxy on Network ESCU actions · hunting P [LLM] BridgeHead SOCKS5 relay drop: unbcl.dll + libwinpthread-1.dll co-located outside System32 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 / reverse shell from TeamCity server process — CVE-2026-63077 Bespoke c2 · hunting DSPDDCS [LLM] BridgeHead WebSocket SOCKS5 tunnel to smartconnect.azurewebsites.net with hardcoded Edg/86 UA Bespoke c2 · alerting DSΣPDDCS [LLM] msaRAT: Connection to Chaos delivery IP / workers.dev signaling relay Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT: Headless browser initiating WebRTC STUN/TURN egress Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT CDP abuse: headless Chrome/Edge with remote-debugging port spawned by non-browser parent Bespoke c2 · alerting DSΣPDDCS [LLM] HelloNet renamed-PuTTY reverse SSH tunnel to 5.39.253.206 Bespoke c2 · alerting DSΣPDDCS [LLM] HelloNet C2 egress to 5.39.253.206 / 176.32.34.135 Bespoke c2 · hunting DSΣPDDCS [LLM] OkoBot 'Apple Sync' scheduled task maintaining reverse SSH tunnel forwarding RDP Bespoke install · alerting DSΣPDDCS [LLM] UAT-7810 ORB relay C2 — outbound to LONGLEASH/DOGLEASH relay IPs Bespoke c2 · hunting DSΣPDDCS [LLM] BusySnake reverse SSH tunnel: ssh.exe -R launched by bundled Python payload Bespoke c2 · hunting DSΣPDDCS [LLM] SoftEther VPN / VNT tunneler masquerading as VMware vmtools.exe Bespoke c2 · hunting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP

Articles citing this technique (14)