internal_socks5_proxy

Explanation

The internal_socks5_proxy NDM is designed to detect socks5 traffic on the local customer network. A SOCKS5 proxy is a protocol that routes internet traffic through a proxy server. It can be used to hide your IP address, bypass internet censorship, and access geo-restricted content. SOCKS5 is an upgraded version of the SOCKS protocol that offers more advanced features such as authentication and encryption. It is commonly used by individuals and organizations to protect their online privacy, improve their online security, and access restricted content.

What to Look For

To examine the results of the internal_socks5_proxy event, customers should check for any instances of socks5 traffic on their network. This includes examining network logs, endpoints, and reviewing any network traffic data. Verification of authorized proxy servers should be conducted.

Related MITRE ATT&CK Categories