Network investigation guide

Investigating SOCKS Tunnel

A SOCKS tunnel carries other network connections through a proxy channel, allowing traffic to cross boundaries through an intermediary.

Tunneling and proxying MITRE ATT&CK: T1572 Protocol Tunneling / T1090 Proxy

What does SOCKS Tunnel mean?

Approved proxies and VPNs rely on tunneling, while attackers use the same capability to bypass segmentation, conceal command-and-control traffic, pivot, or move data.

How to investigate SOCKS Tunnel

  1. 1

    Identify the tunnel endpoints, initiating process, user, protocol, and listening ports.

  2. 2

    Verify whether the software and destination are approved for that host and network zone.

  3. 3

    Determine what traffic is entering the tunnel and which boundaries it crosses.

  4. 4

    Look for persistence, unusual authentication, data transfer, or access to restricted systems.

Common benign explanations

Finding this behavior does not by itself prove malicious intent. Common explanations include:

  • Approved corporate proxies, remote-access VPNs, and concentrators
  • Site-to-site networking and datacenter or cloud overlays
  • Authorized developer or administrator tunneling workflows

When to escalate or de-escalate

Escalate when

  • An unapproved process or endpoint establishes the tunnel.
  • The tunnel crosses restricted zones or carries command, lateral-movement, or exfiltration traffic.

De-escalate when

  • The tunnel maps to approved infrastructure and a documented business purpose.
  • The process, identity, destination, and routing behavior match policy.

Investigate network behavior with Red Hand

Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.