Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4 rules
Suspicious Port Forwarding Configuration via netsh portproxy (via process_creation)
This rule detects configuration of an IPv4 or IPv6 port forwarding rule using netsh portproxy. Fire Ant used netsh portproxy on servers and workstations to pivot and relay traffic deeper into segmented networks, sometimes abusing IPv6 to bypass IPv4 filtering. Network administrators may occasionally use portproxy for legitimate forwarding.
HuntRule TeamWindowsprocess_creationMedium275Premium2026-05-16Malicious Port Forwarding Tunnel via Netsh Portproxy (via process_creation)
This rule detects netsh interface portproxy commands that create a local port-forwarding tunnel, which adversaries use to relay traffic through a compromised host and reach otherwise unreachable internal systems. Netsh portproxy tunneling is a command-and-control and lateral-movement technique in the Red Canary Threat Detection Report. Detecting the tunnel setup surfaces network pivoting through the endpoint.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-05-13Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_eventMedium453Free2021-06-22Windows netsh.EXE Adds Portproxy v4-to-v4 Forwarding Rule
Flags netsh.exe command lines that add portproxy v4-to-v4 forwarding rules on Windows.
Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium83Free2019-01-29