Skip to content

Commit c60da68

Browse files
Update detections/network/cisco_sa___access_to_anonymizer_services.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
1 parent 8076bd0 commit c60da68

1 file changed

Lines changed: 0 additions & 1 deletion

File tree

detections/network/cisco_sa___access_to_anonymizer_services.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,6 @@ description: |
1010
This analytic detects attempts to access proxy-evasion or anonymizer services using Cisco Secure Access DNS and secure web proxy telemetry.
1111
Users who reach anonymizer or proxy-evasion infrastructure are often trying to bypass corporate controls such as secure web gateway inspection, DLP monitoring, CASB visibility, and threat-detection systems. These services frequently establish encrypted tunnels that hide subsequent traffic from inspection.
1212
Early identification helps security teams spot circumvention attempts before potential data exfiltration or follow-on malicious activity. Correlating DNS resolution and proxy session data strengthens confidence that access was intentional.
13-
Activity is mapped to MITRE ATT&CK T1562.001 (Impair Defenses) when categories indicate anonymizer or proxy-evasion infrastructure.
1413
data_source:
1514
- Cisco Secure Access DNS
1615
search: |-

0 commit comments

Comments
 (0)