Pythonw.exe Lateral Movement via Multiplexed SOCKS5 Tunnel - Fan-out to Admin Ports
Detects anomalous pythonw.exe execution from non-standard installation paths that exhibits a fan-out pattern of network connections to multiple sensitive internal administrative ports (445, 3389, 5985, 22, 1433, 135, 389). This behavior is characteristic of lateral movement using a SOCKS5 proxy tunnel, such as the activity observed in the TWINLOOT campaign where implants pivot through reverse tunnels to access internal resources.
Sigma

