Technique.View on attack.mitre.org
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.
Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.
Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.
Rules on DetectionCode tagged with T1572.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco IOS XE Tunnel Interface Configuration | Anomaly | NULL | Cisco IOS Logs |
| Linux Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Ngrok Reverse Proxy on Network | Anomaly | NULL | Sysmon EventID 22 |
| Okta Non-Standard VPN Usage | TTP | NULL | Okta |
| Socat Network Listener Binding an Executable | TTP | NULL | Osquery Results, Sysmon for Linux EventID 1 |
| Socat Remote TCP Connection with Local Echo Disabled | Anomaly | NULL | Osquery Results, Sysmon for Linux EventID 1 |
| Windows Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Potential Cloudflared Network Connection | Hunting | NULL | Sysmon EventID 3 |
| Windows Potential Cloudflared Tunnel Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Protocol Tunneling with Plink | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SoftEther VPN Masquerading as Legitimate Binary | TTP | NULL | Sysmon EventID 1 |
| Windows SSH Proxy Command | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupChimera | Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS. |
| GroupCinnamon Tempest | Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel. |
| GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| GroupEmber Bear | Ember Bear has used ProxyChains to tunnel protocols to internal networks. |
| GroupFIN13 | FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets. |
| GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| GroupFIN7 | FIN7 has tunneled C2 traffic via OpenSSH. |
| GroupFox Kitten | Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion. |
| Used by | Procedure example |
|---|---|
| MalwareBRICKSTORM | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| MalwareCyclops Blink | Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes. |
| MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| MalwareFLIPSIDE | FLIPSIDE uses RDP to tunnel traffic from a victim environment. |
| ToolFRP | FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT. |
| MalwareFunnyDream | FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2. |
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler software to establish a “Yamux” TLS-based C2 channel with an external server(s). |
| CampaignC0027 | During C0027, Scattered Spider used SSH tunneling in targeted environments. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment. |
| CampaignCostaRicto | During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain. |
| CampaignCutting Edge | During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.