Volt Typhoon Netsh PortProxy / Pktmon Network Tunneling T1090.001
Detects the use of native Windows binaries 'netsh.exe' to establish port proxies or 'pktmon.exe' for network packet monitoring/filtering by processes that are not signed by Microsoft. This behavior is indicative of network tunneling or C2 communication techniques used by actors such as Volt Typhoon to maintain persistence and establish network pivots.
SentinelOne

