Windows PortProxy Registry Key Modified for Port Forwarding

Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_event
Author
Andreas Hunkeler (@Karneades) (SigmaHQ), DRL 1.1
Published
2021-06-22
Updated
2026-07-30
title: Windows PortProxy Registry Key Modified for Port Forwarding
id: 46bbc2a3-c418-4f6f-8154-be094d04550d
status: test
description: This rule detects changes to the Windows Registry path used by the PortProxy service for IPv4-to-IPv4 TCP port forwarding configuration. Attackers can abuse PortProxy to create or alter local-to-remote forwarding paths, enabling stealthy redirection of network traffic for lateral movement or command and control. It relies on Windows registry event telemetry that captures modifications to the target PortProxy key path.
references:
  - https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
  - https://adepts.of0x.cc/netsh-portproxy-code/
  - https://www.dfirnotes.net/portproxy_detection/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_portproxy_registry_key.yml
author: Andreas Hunkeler (@Karneades), Huntrule Team
date: 2021-06-22
modified: 2024-03-25
tags:
  - attack.lateral-movement
  - attack.command-and-control
  - attack.t1090
logsource:
  category: registry_event
  product: windows
detection:
  selection:
    TargetObject|contains: \Services\PortProxy\v4tov4\tcp\
  condition: selection
falsepositives:
  - WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
  - Synergy Software KVM (https://symless.com/synergy)
level: medium
license: DRL-1.1
related:
  - id: a54f842a-3713-4b45-8c84-5f136fdebd3c
    type: derived