Linux auditd: iptables NAT redirect execution to altered TCP destination ports

Flags iptables NAT REDIRECT commands with --to-ports values 42–43 observed via Linux auditd EXECVE.

FreeReviewedSigma · Medium · v3
Product
linux
Service
auditd
Author
Rafal Piasecki (SigmaHQ), DRL 1.1
Published
2022-08-10
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies execution of iptables commands that use NAT table redirection to specific destination ports via the --to-ports argument. Such behavior can conceal malicious access by making traffic appear intended for a benign TCP service while redirecting it to an alternate port on the host. Telemetry relies on Linux auditd process execution events (EXECVE) capturing the iptables command line and the presence of the targeted --to-ports values.

Related detections9 linkedT1686 — drag to rearrange
Suspicious Disabling or Flushing of the Linux Host Firewall (via process_creation)
Malicious Firewall Deactivation - PowerShell (via powershell)
Malicious Firewall Deactivation - Firewall (via firewall-as)
Suspicious Outbound Firewall Block Rule Added via Netsh Advfirewall
Malicious Windows Firewall Disable via Netsh
OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
Suspicious Firewall Rule Masquerading as CloudExperienceHost via netsh
Suspicious Firewall Rule Masquerading As Windows Update (via process_creation)
Linux auditd: iptables NAT redirect execution to altered TCP destination ports
Pivot detection · T1686 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.