LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0183: Tor

MITRE ATT&CK S0183: Tor Tool details for Linux, Windows, macOS, with detection guidance, relationships and mapped CVEs.

EnterpriseS0183ToolObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Tor is legitimate anonymity software, but in ATT&CK it matters because adversaries can use it to hide where command-and-control or other network activity is really coming from. For leaders, the issue is not “Tor is bad” by itself; it is whether the organization can distinguish approved privacy use from suspicious use that obscures source attribution, incident scoping, and response decisions across Windows, macOS, and Linux environments.

Executive priority

Prioritize Tor as a visibility and policy question: do business units have a legitimate reason to use anonymizing networks, and can security teams prove when Tor-related traffic is allowed, blocked, or investigated? ATT&CK relationships connect Tor to multiple campaigns and groups, including espionage, ransomware/data extortion, and destructive or infrastructure-focused activity, so unresolved Tor visibility can slow incident response, audit evidence collection, and executive decision-making during high-risk events.

Technical view

Tor is mapped to Multi-hop Proxy (T1090.003) and Asymmetric Cryptography (T1573.002), both under command-and-control in the supplied relationship context. SOC and IR teams should validate whether endpoint, proxy, firewall, DNS, and network telemetry can identify Tor client use, connections to known Tor infrastructure, unusual encrypted outbound sessions, and policy exceptions. Because MITRE provides no official detection text for this object, detection engineering should be environment-specific and should account for legitimate privacy, research, or security-testing use.

Likely telemetry

  • Endpoint process and command-line activity on Windows, macOS, and Linux for Tor-related software execution where collected
  • Network connection metadata for outbound encrypted sessions and proxy-like behavior
  • Firewall, secure web gateway, and proxy logs showing access to Tor-related infrastructure or denied/allowed anonymizer categories
  • DNS resolver logs for Tor-related domains or bootstrap activity where applicable
  • Asset and user context to determine whether Tor use is authorized, expected, or anomalous

Detection direction

  • Start with policy-backed detection: alert differently on unauthorized Tor use, newly observed Tor activity, and Tor activity from sensitive systems.
  • Correlate Tor indicators with the related ATT&CK behaviors: multi-hop proxying and encrypted command-and-control, rather than relying on a single blocklist hit.
  • Tune for false positives from legitimate privacy use, security research, journalism, or sanctioned testing if those apply in the environment.
  • Validate coverage across all supplied Tor platforms: Linux, Windows, and macOS.
  • Review blind spots where TLS inspection is unavailable, endpoint telemetry is weak, DNS is bypassed, or egress logs lack user and asset attribution.

Mitigation priorities

  • Define and approve a business policy for anonymizing network software and document any authorized exceptions.
  • Restrict or monitor unauthorized Tor use through egress controls, proxy policy, firewall rules, and endpoint controls where operationally appropriate.
  • Improve outbound traffic visibility so SOC teams can associate suspicious encrypted or proxy traffic with users, hosts, and business processes.
  • For high-value systems, prioritize tighter egress control and faster IR triage for unexpected Tor-related activity.
  • Include Tor-related evidence requirements in incident response playbooks and compliance/audit artifacts, especially where investigations depend on proving network path, user context, and data movement risk.
Additional notes and limits

The ATT&CK object describes Tor as an anonymity network using multi-hop proxying and layered encryption. Relationship data links it to Multi-hop Proxy and Asymmetric Cryptography techniques and to multiple campaigns and groups, including CostaRicto, Operation Wocao, FLORAHOX Activity, Salesforce Data Exfiltration, 2025 Poland Wiper Attacks, APT28, APT29, Leviathan, Scattered Spider, INC Ransom, and Water Galura. These relationships support prioritizing visibility and response readiness, but they do not by themselves prove malicious activity in any local environment.

MITRE does not provide official detection guidance for this object, and the object has no specified tactics of its own. This take therefore avoids claiming guaranteed detection or active exploitation and depends on local policy, telemetry quality, asset criticality, and business-approved Tor use to determine severity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Tor

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.5
Created
Modified
Raw hash
5bdc86348a52a07b...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.