Detection of Port Proxy Registry Modifications for Protocol Tunneling
Adversaries manipulate the Windows PortProxy registry keys to establish unauthorized port forwarding, enabling lateral movement and the bypassing of network segmentation.
Windows PortProxy is a native component of the IPv6 transition technology that allows for the redirection of TCP traffic between IPv4 and IPv6 addresses, or to different ports on the same or remote machines. Threat actors abuse this functionality by modifying registry keys under HKLM\SYSTEM\*ControlSet*\Services\PortProxy\v4tov4\ to create persistent or temporary port forwarding rules. This technique is often employed as a post-compromise activity to facilitate internal proxying, tunnel malicious traffic, or act as a jump box to traverse network segmentation restrictions. Monitoring these specific registry keys is essential for detecting unauthorized persistence and hidden Command and Control (C2) communication channels. Defenders should focus on process execution context surrounding these registry modifications to identify suspicious administrative activity.
Impact
Successful exploitation allows attackers to bypass network perimeter defenses and segmentation. This enables lateral movement into isolated network segments, redirection of internal traffic to external C2 infrastructure, and the ability to maintain communication channels that may evade traditional network-based security controls.
Recommendation
Prioritize detection and investigation of registry modifications targeting PortProxy configurations.
- Deploy the provided Sigma rule to monitor registry changes under
HKLM\SYSTEM\*ControlSet*\Services\PortProxy\v4tov4\. - Investigate the parent process of any modification to these keys to identify unauthorized administrative activity.
- Audit existing PortProxy rules during incident response to identify and remove unauthorized tunnels used as backdoors.
- Enable Sysmon registry event logging (Event ID 12 or 13) to capture these modifications.
Immediate actions
Deploy PortProxy registry modification detection rule.
Threat Hunt
Search for existing registry keys under PortProxy for unauthorized redirection.
Data: Registry change logs
Mitigations
Remove unauthorized PortProxy rules.
T1090.001
Detection coverage 1
Detect Port Forwarding Rule Addition in Registry
mediumDetects the creation or modification of Windows Registry keys associated with the PortProxy service, often used to bypass network segmentation.
Detection queries are available on the platform. Get full rules →