# internal\_socks5\_proxy

**Explanation**

The internal\_socks5\_proxy NDM is designed to detect socks5 traffic on the local customer network. A SOCKS5 proxy is a protocol that routes internet traffic through a proxy server. It can be used to hide your IP address, bypass internet censorship, and access geo-restricted content. SOCKS5 is an upgraded version of the SOCKS protocol that offers more advanced features such as authentication and encryption. It is commonly used by individuals and organizations to protect their online privacy, improve their online security, and access restricted content.

**What to Look For**

To examine the results of the internal\_socks5\_proxy event, customers should check for any instances of socks5 traffic on their network. This includes examining network logs, endpoints, and reviewing any network traffic data. Verification of authorized proxy servers should be conducted.

**Related MITRE ATT\&CK Categories**

[Command and Control: Proxy, Technique T1090 - Enterprise](https://attack.mitre.org/techniques/T1090)


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.fusion.vectra.ai/detection-models/library/misconfiguration/internal_socks5_proxy.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
