T1090.003 Multi-hop Proxy
Subtécnica de T1090 Proxy
Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- DNS Query Tor .Onion Address - Sysmonhightest · windows
- Query Tor Onion Address - DNS Clienthightest · windows
- Tor Client/Browser Executionhightest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.