Skip to content

Proxy Log

Definition

A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL, user-agent string, HTTP method, response code, and bytes exchanged. The primary source for detecting web-based command-and-control and data exfiltration over HTTP.

Generated by
Forward proxy server
Fields captured
URL, user-agent, HTTP method, response code, bytes
Primary use
Detecting web-based C2 and HTTP exfiltration
Category
Firewall and intrusion detection log analysis

Common questions

How does a proxy log help detect command-and-control traffic that HTTPS encryption otherwise hides?+

Even when payload content is encrypted, a proxy log still records the destination URL, request timing, and byte counts, and beacon-like patterns such as regular small requests to an unfamiliar domain can flag likely C2 activity without decrypting the traffic itself.

What is the difference between a proxy log and a firewall log for investigative purposes?+

A firewall log typically records connection-level data such as source and destination IP and port, while a proxy log operates at the application layer and captures the actual HTTP request details, making it more useful for identifying what web content or service was actually accessed.

Related terms

Anomaly-Based IDS
An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
Five-Tuple
The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...
Lateral Movement
Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
Signature-Based IDS
An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant...
True Positive / False Positive
A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.