T1090.003 Multi-hop Proxy
Sub-technique of T1090 Proxy
Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- DNS Query Tor .Onion Address - Sysmonhightest · windows
- Query Tor Onion Address - DNS Clienthightest · windows
- Tor Client/Browser Executionhightest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.