What MITRE ATT&CK T1090: Proxy (Command and Control) requires
MITRE ATT&CK T1090 covers adversary use of proxy infrastructure (Internal Proxy T1090.001, External Proxy T1090.002, Multi-hop Proxy T1090.003 including Tor, Domain Fronting T1090.004) to obfuscate C2 traffic origin. APT29, Cobalt Strike, Sliver, and most commercial spyware use proxy chains. Compliance: NIST 800-53 SC-7, SI-4, ISO 27001 A.8.20, A.8.21, PCI DSS Req 11.4, NIS2 Article 21(2)(b).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1090/
SHA-256 integrity: 3c017969ed27645397fc673e14422e62d35b2d332b5810ad6f44340076f7f901
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1090: Proxy (https://attack.mitre.org/techniques/T1090/) with 4 sub-techniques
- NIST SP 800-53 Rev 5: SC-7, SI-4
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.