Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1249-1280 of 1801 terms

P
27

Proxy Logs

Logs from web proxies recording the URLs users and systems accessed, including method, response, and often categories, a rich source of telemetry for detecting C2, exfiltration, and policy violations.

Proxy logs capture web traffic that passed through a proxy: source, destination URL, method, response code, bytes, and often the proxy's category for the destination. They are a high-value telemetry source: command-and-control beaconing, data exfiltration to web destinations, access to risky sites, and unusual traffic patterns all show up here. Centralizing proxy logs into the SIEM, alongside DNS and flow data, gives defenders crucial network visibility, especially for web-based attacker behavior.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Spotting beaconing in proxy logs through repeated, regular requests.
  • Detecting exfiltration as unusually large outbound transfers.
  • Investigating which URLs a host accessed during a compromise.

No related terms linked yet.

Q
5