Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0359 — Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling
DET0359

Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1020 Analytic 1020
Windows

Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding.

WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1 dns:query Outbound resolution to hidden service domains (e.g., `.onion`)
[DomainCategory] Can be tuned to `.onion`, I2P, or suspicious CDN domains.
[ProcessParent] Detect known-good vs. abnormal launching binaries (e.g., mshta spawning Tor).
[ConnectionDuration] Threshold for persistent connections over known relay ports (e.g., 9050).
AN1021 Analytic 1021
Linux

Tools such as `tor`, `nglite`, `proxychains`, `chisel`, or custom daemons repeatedly initiate outbound sessions to multiple nodes before final destination. This behavior is abnormal for Linux services outside of VPN, monitoring, or CDN relay contexts.

auditd:SYSCALL execve for proxy tools NSM:Flow conn.log + ssl.log with Tor fingerprinting Netfilter/iptables Forwarded packets log
[ExecutablePath] Match known proxy tools, tuned for environment.
[RelayCount] Detect outbound chaining behavior through >2 IPs in short succession.
[ProtocolType] Allow filtering by ICMP, TCP/443, UDP for obfuscation channels.
AN1022 Analytic 1022
macOS

LaunchAgents or LaunchDaemons initiate persistent Tor or relay processes that make encrypted outbound connections. May be paired with sandbox bypasses or unsigned executables communicating over SOCKS proxies.

macos:unifiedlog process, socket, and DNS logs macos:osquery process_events + launchd macos:unifiedlog forwarded encrypted traffic
[LaunchdLabel] Regex for masking patterns in LaunchAgents with proxy behavior.
[UnsignedBinary] Allow for exceptions for known unsigned binaries.
[SOCKSPortUsage] Monitor local 9050/9150 activity and rerouted system traffic.
AN1023 Analytic 1023
ESXi

Outbound encrypted traffic initiated from hypervisor shell or via VM backdoor mechanisms to relays in VPS infrastructure, especially if traversing multiple nodes before reaching Internet destination. Packet captures or firewall logs show non-VM communication paths.

esxi:esxupdate /var/log/esxupdate.log or /var/log/vmksummary.log esxi:vmkernel /var/log/vmkernel.log NSM:Flow Relay patterns across IP hops
[HopCount] Threshold on number of IPs contacted in sequence without DNS resolution.
[ShellAccess] Flag if relay communication initiated by ESXi shell or unknown VM agent.
[VPSIPRange] Filter for known Tor/VPS egress networks.
AN1024 Analytic 1024
Network Devices

Encrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology.

NSM:Flow Relayed session pathing (multi-hop) NSM:Firewall Outbound encrypted traffic networkdevice:syslog Custom firmware or routing changes
[VPNConfigWhitelist] Define allowed internal router communication paths.
[ICMPPayloadEntropy] High entropy ICMP payloads may indicate tunneling activity.
[RelayChainSignature] Track known multi-hop pattern signatures or port hopping techniques.

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0359
STIX ID
x-mitre-detection-strategy--407286ed-c904-412a-9f2d-7426ea7304a4
Analytics
5
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.