Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF029.006
- Created: 02nd August 2026
- Updated: 02nd August 2026
- Contributor: The ITM Team
Proxy Chaining
A subject routes network traffic through multiple proxy servers, relay services, gateways, or intermediary systems to conceal the final destination of the connection and frustrate attribution.
Unlike the use of a single manually configured proxy, proxy chaining deliberately introduces multiple network hops between the subject’s endpoint and the external destination. Each intermediary may reveal only the preceding and subsequent connection, preventing any single organizational log source from recording the complete route.
The chain may include web proxies, Secure Shell tunnels, SOCKS proxies, commercial anonymity services, cloud-hosted systems, compromised infrastructure, or personally controlled servers. The subject may configure the chain through browser settings, operating-system proxy configuration, command-line utilities, scripts, tunneling applications, or proxy-management software.
Proxy chaining can impede investigation by causing network controls to record only the first proxy in the sequence. It may also separate the subject’s organizational identity and source address from the service ultimately accessed. Where different proxy nodes use encryption or operate across multiple jurisdictions or providers, obtaining a complete record of the activity may be difficult or impossible.
Investigators should distinguish proxy chaining from legitimate multi-layered enterprise network architecture. Relevant factors include whether the intermediary systems were authorized, whether the subject deliberately introduced additional nodes, whether the route bypassed approved inspection infrastructure, and whether the activity was associated with concealed communications, unauthorized access, or data transfer.