Skip to content

SOCKS

SOCKS (Socket Secure) is a protocol that can be leveraged to route network traffic through a proxy server, effectively masking the origin of the traffic and adding a layer of anonymity. While this can be beneficial for protecting user privacy, it also presents a challenge, as attackers might exploit SOCKS proxies to conceal their activities, evade detection, or bypass security controls. It is sometimes used in data exfiltration or C&C activity.

SOCKS in Nzyme

Nzyme parses SOCKS4, SOCKS4A and SOCKS5 traffic. The reported data includes:

  • Source Address
  • Destination Address (Tunnel Server)
  • Tunnel Destination (IP address or hostname)
  • SOCKS Type
  • Timestamps of tunnel establishment, most recent segment and termination

All tunnels are tracked over the duration of their lifetime and assigned a unique ID.

You can find a list of all recorded SOCKS tunnels on the Tunnels page under Ethernet in the sidebar of your Nzyme web interface.

Configuration

The most important SOCKS configuration takes place in your Nzyme tap configuration files:

[protocols.socks]
pipeline_size = 1024
Variable Description
pipeline_size The tap process moves data internally using in-memory pipelines. You may have to increase this value if you experience high throughput of SOCKS segments. (Which is unlikely)