Finding SOCKS with Proxywatch
SpecterOps introduces Proxywatch, a behavioural detection approach for SOCKS proxy tunnels used in lateral movement — addressing a gap where static IOC rules consistently fall short.
Summary written by editorial AI · Source link below
TL;DR: Adversaries use SOCKS proxy tunnels to pivot within environments and to execute code against compromised systems without bringing tools to the system. Defenders often lack reliable guidance to detect proxying behavior, falling back to preset rules based on static indicators or process-port baselines. This blog post highlights Proxywatch, a proof-of-concept release by SpecterOps, to […] The post Finding SOCKS with Proxywatch appeared first on SpecterOps .
Editorial Analysis
Adversaries increasingly tunnel through SOCKS proxies to avoid bringing tools to disk; defenders need behavioural rather than signature-based detection to catch this.
Test Proxywatch's detection logic against your network telemetry and integrate proxy-tunnel hunting into regular threat-hunt cycles.
New research provides defenders with behavioural methods to detect stealthy network tunnelling that conventional rules miss.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at SpecterOps in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d