logo

Living off the land with native SSH and split tunnelling

ID: e75aebf5-71ca-51a7-9e20-9da1bbd3213b

STIX ID: report--e75aebf5-71ca-51a7-9e20-9da1bbd3213b

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-03-06

Date Updated: 2026-03-24

Author: Joe Blogs

...
...

This report explains how attackers can leverage the built-in Windows OpenSSH client to create split-tunnel SSH proxies (dynamic/reverse port forwarding), allowing internal network traffic to be routed through an external server and enabling stealthy operations (e.g., via proxychains) without deploying full C2. It provides minimal setup guidance (SSH keys, SOCKS proxy) and recommends defenses: restrict or remove the SSH client from endpoints, ensure full removal of lingering binaries, and reassess split-tunneling/VPN routing to consolidate monitoring and reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.