Protocol Tunneling

T1572

Technique.View on attack.mitre.org

About this technique

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.

Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.

Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.

Detection rules35

Rules on DetectionCode tagged with T1572.

Sigma23

RuleLevelLog source
Silence.EDA Detectioncriticalwindows / ps_script
Communication To LocaltoNet Tunneling Service Initiatedhighwindows / network_connection
Communication To LocaltoNet Tunneling Service Initiated - Linuxhighlinux / network_connection
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connection
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connection
Potential RDP Tunneling Via Plinkhighwindows / process_creation
Potential RDP Tunneling Via SSHhighwindows / process_creation
Process Initiated Network Connection To Ngrok Domainhighwindows / network_connection
PUA - 3Proxy Executionhighwindows / process_creation
PUA - Ngrok Executionhighwindows / process_creation
RDP Over Reverse SSH Tunnelhighwindows / network_connection
RDP to HTTP or HTTPS Target Portshighwindows / network_connection
Suspicious Plink Port Forwardinghighwindows / process_creation
Cloudflared Tunnel Connections Cleanupmediumwindows / process_creation
Cloudflared Tunnel Executionmediumwindows / process_creation

Splunk12

RuleTypeRiskData source
Cisco IOS XE Tunnel Interface ConfigurationAnomalyNULLCisco IOS Logs
Linux Ngrok Reverse Proxy UsageAnomalyNULLSysmon for Linux EventID 1
Ngrok Reverse Proxy on NetworkAnomalyNULLSysmon EventID 22
Okta Non-Standard VPN UsageTTPNULLOkta
Socat Network Listener Binding an ExecutableTTPNULLOsquery Results, Sysmon for Linux EventID 1
Socat Remote TCP Connection with Local Echo DisabledAnomalyNULLOsquery Results, Sysmon for Linux EventID 1
Windows Ngrok Reverse Proxy UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Potential Cloudflared Network ConnectionHuntingNULLSysmon EventID 3
Windows Potential Cloudflared Tunnel ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Protocol Tunneling with PlinkTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows SoftEther VPN Masquerading as Legitimate BinaryTTPNULLSysmon EventID 1
Windows SSH Proxy CommandAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2

Groups15

Software21

Campaigns6

Procedure examples42

Groups15

Used byProcedure example
GroupChimera

Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS.

GroupCinnamon Tempest

Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel.

GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

GroupEmber Bear

Ember Bear has used ProxyChains to tunnel protocols to internal networks.

GroupFIN13

FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets.

GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

GroupFIN7

FIN7 has tunneled C2 traffic via OpenSSH.

GroupFox Kitten

Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.

View all 15 groups examples

Software21

Used byProcedure example
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

MalwareCobalt Strike

Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

MalwareCyclops Blink

Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes.

MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

MalwareFLIPSIDE

FLIPSIDE uses RDP to tunnel traffic from a victim environment.

ToolFRP

FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT.

MalwareFunnyDream

FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2.

View all 21 software examples

Campaigns6

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler software to establish a “Yamux” TLS-based C2 channel with an external server(s).

CampaignC0027

During C0027, Scattered Spider used SSH tunneling in targeted environments.

CampaignC0032

During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment.

CampaignCostaRicto

During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain.

CampaignCutting Edge

During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads.

References3

  1. BleepingComp Godlua JUL19 Open source
    Gatlan, S. (2019, July 3). New Godlua Malware Evades Traffic Monitoring via DNS over HTTPS. Retrieved March 15, 2020.
  2. SSH Tunneling Open source
    SSH.COM. (n.d.). SSH tunnel. Retrieved March 15, 2020.
  3. Sygnia Abyss Locker 2025 Open source
    Abigail See, Zhongyuan (Aaron) Hau, Ren Jie Yow, Yoav Mazor, Omer Kidron, and Oren Biderman. (2025, February 4). The Anatomy of Abyss Locker Ransomware Attack. Retrieved April 4, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.