kevmap

TechniquesT1090 › AN1233

AN1233 Analytic 1233

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.</p>
Detects
T1090 Proxy
Part of
DET0445 Detection of Proxy Infrastructure Setup and Traffic Bridging

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:FirewallPolicy Change / Rule UpdateDC0051 Firewall Rule Modification
NSM:FlowFlow Creation (NetFlow/sFlow)DC0078 Network Traffic Flow
networkdevice:cliInterface commandsDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
RuleTypeFocus on new allow/permit rules with dynamic NAT or port forwarders.
ChangeUserFlag any non-admins initiating proxy config changes.
FlowVolumeDeltaDetect sharp changes in bi-directional traffic patterns.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped