preventions
- ID: PV006
- Created: 25th May 2024
- Updated: 23rd October 2025
- MITRE ATT&CK®: M1037
- Contributor: The ITM Team
Install a Web Proxy Solution
A web proxy can allow for specific web resources to be blocked, preventing clients from successfully connecting to them.
Sections
| ID | Name | Description |
|---|---|---|
| IF001 | Exfiltration via Web Service | A subject uses an existing, legitimate external Web service to exfiltrate data |
| IF007 | Unlawfully Accessing Copyrighted Material | A subject unlawfully accesses copyrighted material, such as pirated media or illegitimate streaming sites. |
| IF008 | Inappropriate Web Browsing | A subject accesses web content that is deemed inappropriate by the organization. |
| IF009 | Installing Unapproved Software | A subject installs software onto an organization-managed system without prior approval or outside sanctioned methods (e.g., centralized package management, internal software portals). This behavior spans a spectrum of risk - from seemingly benign installations (e.g., video games, personal browsers, media players) to unauthorized deployment of potentially harmful tools sourced from unvetted repositories or adversarial infrastructure.
The infringement may involve:
While some installations may appear harmless, unapproved software installs can represent a breakdown in configuration control and acceptable use. In high-risk scenarios, such software may introduce remote access mechanisms, data exfiltration capabilities, or other malware. Even benign cases signal behavioral drift, particularly when repeated or ignored, and can contribute to software sprawl, policy erosion, or eventual exploitation. |
| IF005 | Exfiltration via Messaging Applications | A subject uses a messaging application to exfiltrate data through messages or uploaded media. |
| ME006 | Web Access | A subject can access the web with an organization device. |
| ME009 | FTP Servers | A subject is able to access external FTP servers. |
| IF017 | Excessive Personal Use | A subject uses organizational resources, such as internet access, email, or work devices, for personal activities both during and outside work hours, exceeding reasonable personal use. This leads to reduced productivity, increased security risks, and the potential mixing of personal and organizational data, ultimately affecting the organization’s efficiency and overall security. |
| IF018 | Sharing on AI Chatbot Platforms | A subject interacts with a public Artificial Intelligence (AI) chatbot (such as ChatGPT and xAI Grok), leading to the intentional or unintentional sharing of sensitive information. |
| IF027 | Installing Malicious Software | The subject deliberately or inadvertently introduces malicious software (commonly referred to as malware) into the organization’s environment. This may occur via manual execution, automated dropper delivery, browser‑based compromise, USB usage, or sideloading through legitimate processes. Malicious software includes trojans, keyloggers, ransomware, credential stealers, remote access tools (RATs), persistence frameworks, or other payloads designed to cause harm, exfiltrate data, degrade systems, or maintain unauthorized control.
Installation of malicious software represents a high-severity infringement, regardless of whether the subject's intent was deliberate or negligent. In some cases, malware introduction is the culmination of prior behavioral drift (e.g. installing unapproved tools or disabling security controls), while in others it may signal malicious preparation or active compromise.
This Section is distinct from general “Installing Unapproved Software”, which covers non‑malicious or policy-violating tools. Here, the software itself is malicious in purpose or impact, even if delivered under benign pretenses. |
| PR038 | AI-Assisted Capability Development | A subject uses artificial intelligence systems to acquire knowledge and understanding that enables them to bypass controls, exploit systems, or perform actions outside of their legitimate business needs.
This behavior involves interacting with AI tools, such as browser-based assistants or integrated software features, to obtain explanations, procedural guidance, or technical instruction that can be directly applied within the organizational environment. Through iterative prompting, the subject refines their understanding, resolves uncertainties, and develops the capability required to execute actions they would not otherwise be able to perform.
Unlike traditional research methods, which rely on static sources and require independent interpretation, AI systems provide responsive, context-aware assistance that accelerates comprehension and reduces the effort required to translate knowledge into action. This allows subjects to overcome technical barriers quickly and operate beyond their expected level of expertise.
The defining characteristic of this behavior is the development of actionable capability through AI-assisted understanding, specifically where that capability can be used to defeat controls, circumvent safeguards, or misuse access. The subject is not simply gathering information, but actively building the means to act in a way that conflicts with organizational policy or intent.
This preparation technique may support a wide range of downstream behaviors across the matrix, including unauthorized access, data manipulation, process circumvention, or anti-forensic activity. The AI system functions as an on-demand technical guide, enabling the subject to operationalize intent without formal training or prior experience. |
| IF001.001 | Exfiltration via Cloud Storage | A subject uses a cloud storage service, such as Dropbox, OneDrive, or Google Drive to exfiltrate data. They will then access that service again on another device to retrieve the data. Examples include (URLs have been sanitized):
|
| IF001.002 | Exfiltration via Code Repository | A subject uses a code repository service, such as GitHub, to exfiltrate data. They will then access that service again on another device to retrieve the data. Examples include (URLs have been sanitized):
|
| IF001.003 | Exfiltration via Text Storage Sites | A subject uses a text storage service, such as Pastebin, to exfiltrate data. They will then access that service again on another device to retrieve the data. Examples include (URLs have been sanitized):
|
| IF001.004 | Exfiltration via Webhook | A subject may use an existing, legitimate external Web service to exfiltrate data. |
| IF007.001 | Downloading Copyrighted Material | A subject uses a website or peer-to-peer (P2P) network (such as BitTorrent) to unlawfully download copyrighted material. |
| IF007.002 | Streaming Copyrighted Material | A subject accesses a website that allows for the unauthorized streaming of copyrighted material. |
| IF007.003 | Distributing Copyrighted Material | A subject uses a website or peer-to-peer (P2P) network (such as BitTorrent) to unlawfully distribute copyrighted material. |
| IF008.001 | Lawful Pornography | A subject accesses lawful pornographic material from an organization device, contravening internal policies on acceptable use of organization equipment. |
| IF008.002 | Unlawful Pornography | A subject accesses unlawful pornographic material from a organization device, contravening internal policies on acceptable use of organization equipment and potentially, the law. |
| IF008.003 | Terrorist Content | A subject accesses, possesses and/or distributes materials that advocate, promote, or incite unlawful acts of violence intended to further political, ideological or religious aims (terrorism). |
| IF008.004 | Extremist Content | A person accesses, possesses, or distributes materials that advocate, promote, or incite extreme ideological, political, or religious views, often encouraging violence or promoting prejudice against individuals or groups. |
| IF008.005 | Gambling | A subject accesses or participates in online gambling from a corporate device, contravening internal policies on acceptable use of company equipment. |
| IF008.007 | Gaming | A subject accesses or participates in web-based online gaming from a corporate device, contravening internal policies on acceptable use of company equipment. |
| IF008.008 | Other Inappropriate Content | A subject accesses other inappropriate web content from a corporate device, contravening internal policies on acceptable use of company equipment. |
| ME006.001 | Webmail | A subject can access personal webmail services in a browser. |
| ME006.002 | Cloud Storage Websites | A subject can access cloud storage websites. |
| ME006.003 | Inappropriate Websites | A subject can access websites containing inappropriate content. |
| ME006.004 | Note-Taking Websites | A subject can access external note-taking websites. |
| ME006.005 | Messenger Services | A subject can access external messenger web-applications with the ability to transmit data and/or files. |
| ME006.006 | Code Repositories | A subject can access websites used to access or manage code repositories. |
| IF001.005 | Exfiltration via Note-Taking Web Services | A subject uploads confidential organization data to a note-taking web service, such as Evernote. The subject can then access the confidential data outside of the organization from another device. Examples include (URLs have been sanitized):
|
| ME006.007 | Text Storage Websites | A subject can access external text storage websites, such as Pastebin. |
| IF010.002 | Exfiltration via Personal Email | A subject exfiltrates information using a mailbox they own or have access to, either via software or webmail. They will access the conversation at a later date to retrieve information on a different system. |
| IF001.006 | Exfiltration via Generative AI Platform | The subject transfers sensitive, proprietary, or classified information into an external generative AI platform through text input, file upload, API integration, or embedded application features. This results in uncontrolled data exposure to third-party environments outside organizational governance, potentially violating confidentiality, regulatory, or contractual obligations.
Characteristics
Example ScenarioA subject copies sensitive internal financial projections into a public generative AI chatbot to "optimize" executive presentation materials. The AI provider, per its terms of use, retains inputs for service improvement and model fine-tuning. Sensitive data—now stored outside corporate control—becomes vulnerable to exposure through potential data breaches, subpoena, insider misuse at the service provider, or future unintended model outputs. |
| IF009.006 | Installing Crypto Mining Software | The subject installs and operates unauthorized cryptocurrency mining software on organizational systems, leveraging compute, network, and energy resources for personal financial gain. This activity subverts authorized system use policies, degrades operational performance, increases attack surface, and introduces external control risks.
Characteristics
Example ScenarioA subject installs a customized |
| IF001.007 | Exfiltration via Collaboration Platform | A subject uses a cloud collaboration platform, such as Slack, Google Docs, Atlassian Confluence, or Microsoft 365 Online, to exfiltrate data. They will then access that service again on another device to retrieve the data. Examples include (URLs have been sanitized):
|
| IF027.001 | Infostealer Deployment | The subject deploys credential-harvesting malware (commonly referred to as an infostealer) to extract sensitive authentication material or session artifacts from systems under their control. These payloads are typically configured to capture data from browser credential stores (e.g.,
Infostealers may be executed directly via compiled binaries, staged through malicious document macros, or loaded reflectively into memory using PowerShell, .NET assemblies, or process hollowing techniques. Some variants are fileless and reside entirely in memory, while others create persistence via registry keys (e.g.,
While often associated with external threat actors, insider deployment of infostealers allows subjects to bypass authentication safeguards, impersonate peers, or exfiltrate internal tokens for later use or sale. In cases where data is not immediately exfiltrated, local staging (e.g., in |
| IF001.008 | Exfiltration via File-Sharing Platform | The subject uploads organizational data to a personal or unauthorized file-sharing platform (e.g., Dropbox, Google Drive, WeTransfer, MEGA, or similar) to remove it from controlled environments. This technique is commonly used to bypass endpoint restrictions, avoid detection by traditional DLP systems, and facilitate remote access to stolen data. Uploads may occur through browser sessions, desktop clients, or command-line tools, depending on the sophistication of the subject and the controls in place.
Investigators should evaluate whether the data transferred was sensitive, proprietary, or otherwise restricted, and assess whether the subject attempted to conceal or stage the transfer using obfuscation or anti-forensics techniques. |
| ME006.008 | Generative AI Websites | A subject can access generative AI websites. |
| IF043.005 | Working-Time Diversion | A subject deliberately uses substantial paid working time for sustained activity unrelated to their organizational responsibilities. This should exclude minor personal use permitted under the Acceptable Use Policy. |
| AF029.006 | Proxy Chaining | A subject routes network traffic through multiple proxy servers, relay services, gateways, or intermediary systems to conceal the final destination of the connection and frustrate attribution.
Unlike the use of a single manually configured proxy, proxy chaining deliberately introduces multiple network hops between the subject’s endpoint and the external destination. Each intermediary may reveal only the preceding and subsequent connection, preventing any single organizational log source from recording the complete route.
The chain may include web proxies, Secure Shell tunnels, SOCKS proxies, commercial anonymity services, cloud-hosted systems, compromised infrastructure, or personally controlled servers. The subject may configure the chain through browser settings, operating-system proxy configuration, command-line utilities, scripts, tunneling applications, or proxy-management software.
Proxy chaining can impede investigation by causing network controls to record only the first proxy in the sequence. It may also separate the subject’s organizational identity and source address from the service ultimately accessed. Where different proxy nodes use encryption or operate across multiple jurisdictions or providers, obtaining a complete record of the activity may be difficult or impossible.
Investigators should distinguish proxy chaining from legitimate multi-layered enterprise network architecture. Relevant factors include whether the intermediary systems were authorized, whether the subject deliberately introduced additional nodes, whether the route bypassed approved inspection infrastructure, and whether the activity was associated with concealed communications, unauthorized access, or data transfer. |
| AF029.007 | Destination Disguising | A subject causes network activity to appear directed toward an approved, trusted, or otherwise benign service while the underlying communication is routed to a different destination.
Destination disguising may exploit differences between the hostname, certificate, application request, routing layer, or infrastructure used to establish and process a connection. To organizational monitoring, the traffic may initially appear associated with a common cloud, content-delivery, hosting, or software service, while the actual request is forwarded to infrastructure controlled by or selected by the subject.
Methods may include domain fronting, manipulation of host headers, use of shared content-delivery infrastructure, concealed redirects, or the abuse of legitimate cloud services as intermediary routing points. The subject may select these methods because blocking the apparent destination would disrupt legitimate organizational activity.
This behavior can frustrate domain filtering, proxy review, firewall enforcement, and investigative attribution. Security controls may record the visible front domain or shared infrastructure address without identifying the concealed destination or service reached through it.
Investigators should examine Domain Name System records, Transport Layer Security handshake information, Server Name Indication values, certificates, Hypertext Transfer Protocol headers, proxy records, redirects, and destination infrastructure. Differences between these sources may indicate that the apparent and actual destinations do not align.
The use of shared cloud or content-delivery infrastructure does not itself establish obfuscation. Classification should require evidence that the subject deliberately used the discrepancy to conceal the true destination or evade organizational monitoring. |
| PR040.004 | Testing Network Security Controls | A subject performs limited network activity to determine whether firewalls, network segmentation, Domain Name System filtering, web proxies, intrusion detection systems, or protocol restrictions identify or block the connection.
The subject may attempt to reach a prohibited domain, connect to a restricted port, access another network segment, use an unapproved protocol, configure a proxy, or send a small amount of traffic through a normally restricted route. The objective is to establish whether the network path is available and whether the activity produces an alert or investigative response.
Testing may be repeated across different destinations, ports, protocols, systems, or times of day. A subject may use the results to select a less monitored network route, bypass segmentation, communicate with external infrastructure, or prepare a data-transfer channel. |
MITRE ATT&CK® Mapping (1)
ATT&CK Enterprise Matrix Version 19.1