New PortProxy Registry Entry Added

 Original Source: [Sigma source]
Title: New PortProxy Registry Entry Added
Status: test
Description:Detects the modification of the PortProxy registry key which is used for port forwarding.
References:
  -https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
  -https://adepts.of0x.cc/netsh-portproxy-code/
  -https://www.dfirnotes.net/portproxy_detection/
Author: Andreas Hunkeler (@Karneades)
Date: 2021-06-22
modified:2024-03-25
Tags:
  • -'attack.lateral-movement'
  • -'attack.command-and-control'
  • -'attack.t1090'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Services\PortProxy\v4tov4\tcp\'
  condition:selection
Falsepositives:
  -WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
  -Synergy Software KVM (https://symless.com/synergy)
Level: medium