Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0006 — Detection Strategy for Network Boundary Bridging
DET0006

Detection Strategy for Network Boundary Bridging

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0015 Analytic 0015
Network Devices

From a defender’s perspective, suspicious bridging is observed when network devices begin allowing traffic that contradicts existing segmentation or access policies. Observable behaviors include sudden modifications to ACLs or firewall rules, unusual cross-boundary traffic flows (e.g., east-west communications across separated VLANs), or simultaneous ingress/egress anomalies. Multi-event correlation is key: configuration changes on a router/firewall followed by unexpected traffic patterns, especially from unusual sources, is a strong indicator of compromise.

NSM:Flow Unexpected flows between segmented networks or prohibited ports networkdevice:syslog ACL/Firewall rule modification or new route injection
[TimeWindow] Correlation window between configuration changes and abnormal traffic; tuned to match expected administrative change cycles.
[ApprovedChangeList] Known authorized ACL/firewall changes; suppresses noise from legitimate maintenance.
[GeoLocation] Geographic origin of new traffic patterns; helps distinguish benign remote offices from suspicious foreign access.
[TrafficVolumeThreshold] Volume of cross-segment traffic; tuned to detect large-scale lateral flows without flagging small test connections.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0006
STIX ID
x-mitre-detection-strategy--f0f7aa93-71bc-4c55-9f96-9c74a7d45a83
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.