Techniques › T1090.002 › AN0926
AN0926 Analytic 0926
Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Changes to NAT/firewall policies enabling outbound port forwarding from internal IPs to Internet-based proxy endpoints. Log spikes in outbound flows to CDN, VPS, or anomalous ASNs with few return packets.</p>
- Detects
- T1090.002 External Proxy
- Part of
- DET0325 External Proxy Behavior via Outbound Relay to Intermediate Infrastructure
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Firewall Audit Logs | Outbound NAT Rule Changes | DC0051 Firewall Rule Modification |
| NSM:Flow | Outbound flow records | DC0078 Network Traffic Flow |
| networkdevice:syslog | Dynamic route changes | DC0082 Network Connection Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
FlowThreshold | Number of flows or bytes transferred per minute—flag surges to unrecognized ASNs. |
DestinationIPCategory | Proxy destination categories: CDN, TOR exit node, anonymous hosting. |
ConfigChangeUser | Track if unexpected user or automation changed NAT/forwarding rules. |