Threadlinqs IntelligenceStart free

ATT&CK techniqueCommand and Control

T1572 Protocol Tunneling

Command and ControlEnterprise

As of 2026-10-05, T1572 (Protocol Tunneling) appears in 235 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Storm-2603, The Gentlemen, Cavern Manticore; it most often appears alongside T1190 (Exploit Public-Facing Application).

Tracked threats
235104 critical, 124 high, 5 medium
First seen
2026-02-02
Last seen
2026-10-03
Threat actors
96In the threats using it
Detection rules
386Blue tier and above

Data as of:

Activity timeline

T1572 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 73 reports, and 235 of the 235 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1572 Protocol Tunneling is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 235 of 2623 tracked threats (9%) to it; by severity that is 104 critical, 124 high, 5 medium.

Threats that use T1572 most often also use T1190 Exploit Public-Facing Application (134 threats), T1027 Obfuscated Files or Information (131 threats), T1082 System Information Discovery (115 threats), T1059 Command and Scripting Interpreter (113 threats), T1005 Data from Local System (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

96 tracked threat actors appear in the threats that use T1572; the most frequent are Storm-2603 (5), The Gentlemen (5), Cavern Manticore (4), Qilin (4), Static Tundra (4).

Mitigations

MITRE ATT&CK lists 2 mitigations for T1572.

Data sources

Telemetry that can reveal T1572, per MITRE ATT&CK.

  • Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

Threat actors using it

Tracked threats

The 30 most recent of 235 tracked threats that use T1572.

Detection coverage

Threadlinqs maintains 386 detection rules mapped to T1572 (SPL 143, KQL 118, Sigma 125). Rule content is available to Blue tier accounts and above; this page shows counts only.

386 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans