{"id":"T1599.001","name":"Network Address Translation Traversal","url":"https://attack.mitre.org/techniques/T1599/001","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0163","stix_id":"x-mitre-detection-strategy--218a24ca-9534-44e2-9282-fb08373e7845","name":"Detection Strategy for Network Address Translation Traversal","url":"https://attack.mitre.org/detectionstrategies/DET0163","analytics":[{"id":"AN0465","stix_id":"x-mitre-analytic--72033f2d-a943-40be-862c-051317ec541c","name":"Analytic 0465","description":"Defenders may observe unauthorized or anomalous changes to NAT configurations, including the addition of new translation rules or modifications to existing ones. Suspicious behaviors include sudden introduction of NAT mappings bridging segmented networks, new port address translation rules that obscure true source IPs, or traffic flows inconsistent with expected network design. Multi-event correlation includes detecting configuration changes on routers/firewalls, followed by traffic traversing unexpected internal/external address pairs.","url":"https://attack.mitre.org/detectionstrategies/DET0163#AN0465","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"NAT table modification (add/update/delete rule)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"networkdevice-config"},{"name":"NSM:Flow","channel":"Source/destination IP translation inconsistent with intended policy","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Time correlation window between NAT rule change and unexpected traffic; adjustable to align with change management practices."},{"field":"AuthorizedNATRules","description":"Whitelist of approved NAT policies and rules; prevents false positives from legitimate operations."},{"field":"TrafficVolumeThreshold","description":"Threshold for abnormal traffic across NAT; tuned to differentiate testing from large-scale exfiltration or bridging."},{"field":"InterfaceScope","description":"Specific interfaces or zones monitored for NAT translation; allows tuning for internal vs. external-facing boundaries."}],"live":true,"detection_strategies":["DET0163"],"techniques":["T1599.001"]}],"live":true,"version":"1.0","techniques":["T1599.001"]}],"sigma_rules":[{"id":"679085d5-f427-4484-9f58-1dc30a7c426d","title":"WinDivert Driver Load","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-30","modified":"2024-11-23","description":"Detects the load of the Windiver driver, a powerful user-mode capture/sniffing/modification/blocking/re-injection package for Windows","references":["https://reqrypt.org/windivert-doc.html","https://rastamouse.me/ntlm-relaying-via-cobalt-strike/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.credential-access","attack.collection","attack.defense-impairment","attack.t1599.001","attack.t1557.001"],"path":"rules/windows/driver_load/driver_load_win_windivert.yml","techniques":["T1599.001","T1557.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}