Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
- Product
- windows
- Category
- registry_event
- Author
- Andreas Hunkeler (@Karneades) (SigmaHQ), DRL 1.1
- Published
- 2021-06-22
- Updated
- 2026-07-30
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule detects changes to the Windows Registry path used by the PortProxy service for IPv4-to-IPv4 TCP port forwarding configuration. Attackers can abuse PortProxy to create or alter local-to-remote forwarding paths, enabling stealthy redirection of network traffic for lateral movement or command and control. It relies on Windows registry event telemetry that captures modifications to the target PortProxy key path.
Reporting behind it
- fireeye.comhttps://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
- adepts.of0x.cchttps://adepts.of0x.cc/netsh-portproxy-code/
- dfirnotes.nethttps://www.dfirnotes.net/portproxy_detection/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_portproxy_registry_key.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows PortProxy Registry Key Modified for Port Forwarding
id: 46bbc2a3-c418-4f6f-8154-be094d04550d
status: test
description: This rule detects changes to the Windows Registry path used by the PortProxy service for IPv4-to-IPv4 TCP port forwarding configuration. Attackers can abuse PortProxy to create or alter local-to-remote forwarding paths, enabling stealthy redirection of network traffic for lateral movement or command and control. It relies on Windows registry event telemetry that captures modifications to the target PortProxy key path.
references:
- https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
- https://adepts.of0x.cc/netsh-portproxy-code/
- https://www.dfirnotes.net/portproxy_detection/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_portproxy_registry_key.yml
author: Andreas Hunkeler (@Karneades), Huntrule Team
date: 2021-06-22
modified: 2024-03-25
tags:
- attack.lateral-movement
- attack.command-and-control
- attack.t1090
logsource:
category: registry_event
product: windows
detection:
selection:
TargetObject|contains: \Services\PortProxy\v4tov4\tcp\
condition: selection
falsepositives:
- WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
- Synergy Software KVM (https://symless.com/synergy)
level: medium
license: DRL-1.1
related:
- id: a54f842a-3713-4b45-8c84-5f136fdebd3c
type: derived