kevmap

TechniquesT1090.001 › AN0208

AN0208 Analytic 0208

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Configuration of internal NAT or proxy rules that redirect traffic between client segments internally (e.g., site-to-site port forwarding). Often used to relay internal beaconing or move traffic laterally through trust zones.</p>
Detects
T1090.001 Internal Proxy
Part of
DET0075 Internal Proxy Behavior via Lateral Host-to-Host C2 Relay

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
Firewall Audit LogsConfig ChangeDC0051 Firewall Rule Modification
NSM:FlowInter-segment trafficDC0078 Network Traffic Flow
networkdevice:cliPolicy UpdateDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ProxyTargetInternal subnets or endpoint roles allowed for port forwarding.
ConfigChangeUserDetect changes made outside scheduled or authorized windows.
FlowThresholdVolume of data relayed through proxy exceeds historical norms.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-22017VMware vCenter ServerMapped