logo

StreamDivert: Relaying (specific) network connections

ID: aeb4fecc-308d-51a0-92ff-dcc127b0e804

STIX ID: report--aeb4fecc-308d-51a0-92ff-dcc127b0e804

Feed Name: Fox-IT blog

Threat Score
65/100

Date Published: 2020-09-10

Date Updated: 2026-04-27

Author: Fox It

...
...

This blog describes StreamDivert, an open-source userland tool leveraging the WinDivert kernel driver to intercept and relay inbound and outbound network connections for MITM purposes (including relaying SMB to capture authentication hashes). The author recounts a red-team scenario that motivated the tool, details StreamDivert's capabilities (selective relaying by port or source IP, SOCKS handling, TCP/UDP/ICMP over IPv4/IPv6), and provides detection guidance based on event log entries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.