Proxy Log
Definition
A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL, user-agent string, HTTP method, response code, and bytes exchanged. The primary source for detecting web-based command-and-control and data exfiltration over HTTP.
- Generated by
- Forward proxy server
- Fields captured
- URL, user-agent, HTTP method, response code, bytes
- Primary use
- Detecting web-based C2 and HTTP exfiltration
- Category
- Firewall and intrusion detection log analysis
Common questions
How does a proxy log help detect command-and-control traffic that HTTPS encryption otherwise hides?+
Even when payload content is encrypted, a proxy log still records the destination URL, request timing, and byte counts, and beacon-like patterns such as regular small requests to an unfamiliar domain can flag likely C2 activity without decrypting the traffic itself.
What is the difference between a proxy log and a firewall log for investigative purposes?+
A firewall log typically records connection-level data such as source and destination IP and port, while a proxy log operates at the application layer and captures the actual HTTP request details, making it more useful for identifying what web content or service was actually accessed.
Related terms
- Anomaly-Based IDS
- An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
- Five-Tuple
- The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Signature-Based IDS
- An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant...
- True Positive / False Positive
- A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic....