{"id":"T1572","name":"Protocol Tunneling","url":"https://attack.mitre.org/techniques/T1572","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0538","stix_id":"x-mitre-detection-strategy--fff8e15e-f7eb-4c07-8b77-8e7ef2eb01b6","name":"Detection Strategy for Protocol Tunneling accross OS platforms.","url":"https://attack.mitre.org/detectionstrategies/DET0538","analytics":[{"id":"AN1483","stix_id":"x-mitre-analytic--64c6aa46-a824-4c8e-8462-d0a58b78acfb","name":"Analytic 1483","description":"Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.","url":"https://attack.mitre.org/detectionstrategies/DET0538#AN1483","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedTools","description":"Whitelist legitimate tunneling tools (e.g., used by admins)."},{"field":"DataAsymmetryThreshold","description":"Ratio of sent vs received bytes that indicates tunneling activity."},{"field":"TimeWindow","description":"Correlate process creation with network connection within N seconds."}],"live":true,"detection_strategies":["DET0538"],"techniques":["T1572"]},{"id":"AN1484","stix_id":"x-mitre-analytic--5acd81f3-466a-472d-bb1f-9bda231ac4c0","name":"Analytic 1484","description":"sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0538#AN1484","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket/connect calls showing SSH processes forwarding arbitrary ports","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"sshd sessions with unusual port forwarding parameters","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"socat, ssh, or nc processes opening unexpected ports","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"ForwardingFlags","description":"Specific sshd config flags indicating port forwarding."},{"field":"ProtocolBaseline","description":"Define expected application protocols by port to catch tunneling mismatches."}],"live":true,"detection_strategies":["DET0538"],"techniques":["T1572"]},{"id":"AN1485","stix_id":"x-mitre-analytic--359ab8ab-f306-4e67-8ff4-f8e1c8ec7db3","name":"Analytic 1485","description":"launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0538#AN1485","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process execution of ssh with -L/-R forwarding flags","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"encrypted outbound traffic carrying unexpected application data","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExpectedDoHResolvers","description":"Known legitimate DoH resolvers used in environment."},{"field":"PayloadEntropyThreshold","description":"Flag excessive randomness in payloads on standard ports."}],"live":true,"detection_strategies":["DET0538"],"techniques":["T1572"]},{"id":"AN1486","stix_id":"x-mitre-analytic--7f128f2c-5b38-4088-9026-e251237f8add","name":"Analytic 1486","description":"VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.","url":"https://attack.mitre.org/detectionstrategies/DET0538#AN1486","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"ESXi processes relaying traffic via SSH or unexpected ports","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vpxd"},{"name":"esxcli:network","channel":"listening sockets bound with non-standard encapsulated protocols","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxcli-network"}],"mutable_elements":[{"field":"ESXiServiceProfiles","description":"Baseline allowed services and expected ports for ESXi management."}],"live":true,"detection_strategies":["DET0538"],"techniques":["T1572"]}],"live":true,"version":"1.0","techniques":["T1572"]}],"sigma_rules":[{"id":"18249279-932f-45e2-b37a-8925f2597670","title":"Process Initiated Network Connection To Ngrok Domain","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-16","modified":"2025-07-30","description":"Detects an executable initiating a network connection to \"ngrok\" domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://ngrok.com/","https://ngrok.com/blog-post/new-ngrok-domains","https://www.virustotal.com/gui/file/cca0c1182ac114b44dc52dd2058fcd38611c20bb6b5ad84710681d38212f835a/","https://www.rnbo.gov.ua/files/2023_YEAR/CYBERCENTER/november/APT29%20attacks%20Embassies%20using%20CVE-2023-38831%20-%20report%20en.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok.yml","techniques":["T1567","T1572","T1102"],"cves":[]},{"id":"19bf6fdb-7721-4f3d-867f-53467f6a5db6","title":"Communication To Ngrok Tunneling Service - Linux","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":null,"description":"Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/linux/network_connection/net_connection_lnx_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"1cb0c6ce-3d00-44fc-ab9c-6d6d577bf20b","title":"DNS Query To Devtunnels Domain","author":"citron_ninja","status":"test","level":"medium","date":"2023-10-25","modified":"2023-11-20","description":"Detects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://blueteamops.medium.com/detecting-dev-tunnels-16f0994dc3e2","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/security","https://cydefops.com/devtunnels-unleashed"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1572"],"path":"rules/windows/dns_query/dns_query_win_devtunnels_communication.yml","techniques":["T1071.001","T1572"],"cves":[]},{"id":"1d08ac94-400d-4469-a82f-daee9a908849","title":"Communication To Ngrok Tunneling Service Initiated","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":"2024-02-02","description":"Detects an executable initiating a network connection to \"ngrok\" tunneling domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"327f48c1-a6db-4eb8-875a-f6981f1b0183","title":"Port Forwarding Activity Via SSH.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-12","modified":"2024-03-05","description":"Detects port forwarding activity via SSH.exe","references":["https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.lateral-movement","attack.t1572","attack.t1021.001","attack.t1021.004"],"path":"rules/windows/process_creation/proc_creation_win_ssh_port_forward.yml","techniques":["T1572","T1021.001","T1021.004"],"cves":[]},{"id":"3ab65069-d82a-4d44-a759-466661a082d1","title":"Communication To LocaltoNet Tunneling Service Initiated","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"3ceb2083-a27f-449a-be33-14ec1b7cc973","title":"Silence.EDA Detection","author":"Alina Stepchenkova, Group-IB, oscd.community","status":"test","level":"critical","date":"2019-11-01","modified":"2023-04-03","description":"Detects Silence EmpireDNSAgent as described in the Group-IP report","references":["https://www.group-ib.com/resources/threat-research/silence_2.0.going_global.pdf"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.t1059.001","attack.command-and-control","attack.t1071.004","attack.t1572","attack.impact","attack.t1529","attack.g0091","attack.s0363"],"path":"rules/windows/powershell/powershell_script/posh_ps_apt_silence_eda.yml","techniques":["T1059.001","T1071.004","T1572","T1529"],"cves":[]},{"id":"48a61b29-389f-4032-b317-b30de6b95314","title":"Suspicious Plink Port Forwarding","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-01-19","modified":"2022-10-09","description":"Detects suspicious Plink tunnel port forwarding to a local port","references":["https://www.real-sec.com/2019/04/bypassing-network-restrictions-through-rdp-tunneling/","https://medium.com/@informationsecurity/remote-ssh-tunneling-with-plink-exe-7831072b3d7d"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001"],"path":"rules/windows/process_creation/proc_creation_win_plink_port_forwarding.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"4b657234-038e-4ad5-997c-4be42340bce4","title":"Network Connection Initiated To Visual Studio Code Tunnels Domain","author":"Kamran Saifullah","status":"test","level":"medium","date":"2023-11-20","modified":null,"description":"Detects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://ipfyx.fr/post/visual-studio-code-tunnel/","https://badoption.eu/blog/2023/01/31/code_c2.html","https://cydefops.com/vscode-data-exfiltration"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_vscode_tunnel_connection.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"5f699bc5-5446-4a4a-a0b7-5ef2885a3eb4","title":"RDP Over Reverse SSH Tunnel","author":"Samir Bousseaden","status":"test","level":"high","date":"2019-02-16","modified":"2024-03-12","description":"Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389","references":["https://twitter.com/cyb3rops/status/1096842275437625346"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/network_connection/net_connection_win_rdp_reverse_tunnel.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"5fc297ae-25b6-488a-8f25-cc12ac29b744","title":"Potentially Suspicious Usage Of Qemu","author":"Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR)","status":"test","level":"medium","date":"2024-06-03","modified":null,"description":"Detects potentially suspicious execution of the Qemu utility in a Windows environment.\nThreat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.\n","references":["https://securelist.com/network-tunneling-with-qemu/111803/","https://www.qemu.org/docs/master/system/invocation.html#hxtool-5"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_qemu_suspicious_execution.yml","techniques":["T1090","T1572"],"cves":[]},{"id":"7050bba1-1aed-454e-8f73-3f46f09ce56a","title":"Cloudflared Tunnel Connections Cleanup","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-21","description":"Detects execution of the \"cloudflared\" tool with the tunnel \"cleanup\" flag in order to cleanup tunnel connections.","references":["https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_cleanup.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"7cd1dcdc-6edf-4896-86dc-d1f19ad64903","title":"Network Connection Initiated To Cloudflared Tunnels Domains","author":"Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-05-27","modified":null,"description":"Detects network connections to Cloudflared tunnels domains initiated by a process on the system.\nAttackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://defr0ggy.github.io/research/Abusing-Cloudflared-A-Proxy-Service-To-Host-Share-Applications/","https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/","Internal Research"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_cloudflared_communication.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"9501f8e6-8e3d-48fc-a8a6-1089dd5d7ef4","title":"Network Connection Initiated To DevTunnels Domain","author":"Kamran Saifullah","status":"test","level":"medium","date":"2023-11-20","modified":null,"description":"Detects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://blueteamops.medium.com/detecting-dev-tunnels-16f0994dc3e2","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/security","https://cydefops.com/devtunnels-unleashed"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567.001","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_devtunnels.yml","techniques":["T1567.001","T1572"],"cves":[]},{"id":"9a019ffc-3580-4c9d-8d87-079f7e8d3fd4","title":"Cloudflared Tunnel Execution","author":"Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-20","description":"Detects execution of the \"cloudflared\" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.","references":["https://blog.reconinfosec.com/emergence-of-akira-ransomware-group","https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_run.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"9e02c8ec-02b9-43e8-81eb-34a475ba7965","title":"Network Connection Initiated To BTunnels Domains","author":"Kamran Saifullah","status":"test","level":"medium","date":"2024-09-13","modified":null,"description":"Detects network connections to BTunnels domains initiated by a process on the system.\nAttackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://defr0ggy.github.io/research/Utilizing-BTunnel-For-Data-Exfiltration/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_btunnels.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"a1d9eec5-33b2-4177-8d24-27fe754d0812","title":"Cloudflared Tunnels Related DNS Requests","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-12-20","modified":null,"description":"Detects DNS requests to Cloudflared tunnels domains.\nAttackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/","Internal Research"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1572"],"path":"rules/windows/dns_query/dns_query_win_cloudflared_communication.yml","techniques":["T1071.001","T1572"],"cves":[]},{"id":"b1e5da3b-ca8e-4adf-915c-9921f3d85481","title":"RDP to HTTP or HTTPS Target Ports","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-29","modified":"2022-07-14","description":"Detects svchost hosting RDP termsvcs communicating to target systems on TCP port 80 or 443","references":["https://twitter.com/tekdefense/status/1519711183162556416?s=12&t=OTsHCBkQOTNs1k3USz65Zg","https://www.mandiant.com/resources/bypassing-network-restrictions-through-rdp-tunneling"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/network_connection/net_connection_win_rdp_to_http.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"c4568f5d-131f-4e78-83d4-45b2da0ec4f1","title":"Communication To LocaltoNet Tunneling Service Initiated - Linux","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/linux/network_connection/net_connection_lnx_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"c75309a3-59f8-4a8d-9c2c-4c927ad50555","title":"Tunneling Tool Execution","author":"Daniil Yugoslavskiy, oscd.community","status":"test","level":"medium","date":"2019-10-24","modified":"2024-01-18","description":"Detects the execution of well known tools that can be abused for data exfiltration and tunneling.","references":["https://www.microsoft.com/en-us/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1041","attack.t1572","attack.t1071.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_exfil_and_tunneling_tool_execution.yml","techniques":["T1041","T1572","T1071.001"],"cves":[]},{"id":"ee37eb7c-a4e7-4cd5-8fa4-efa27f1c3f31","title":"PUA - Ngrok Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-05-14","modified":"2023-02-21","description":"Detects the use of Ngrok, a utility used for port forwarding and tunneling, often used by threat actors to make local protected services publicly available.\nInvolved domains are bin.equinox.io for download and *.ngrok.io for connections.\n","references":["https://ngrok.com/docs","https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html","https://stackoverflow.com/questions/42442320/ssh-tunnel-to-ngrok-and-initiate-rdp","https://www.virustotal.com/gui/file/58d21840d915aaf4040ceb89522396124c82f325282f805d1085527e1e2ccfa1/detection","https://cybleinc.com/2021/02/15/ngrok-platform-abused-by-hackers-to-deliver-a-new-wave-of-phishing-attacks/","https://twitter.com/xorJosh/status/1598646907802451969","https://www.softwaretestinghelp.com/how-to-use-ngrok/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_pua_ngrok.yml","techniques":["T1572"],"cves":[]},{"id":"f38a82d2-fba3-4781-b549-525efbec8506","title":"PUA - 3Proxy Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-09-13","modified":"2023-02-21","description":"Detects the use of 3proxy, a tiny free proxy server","references":["https://github.com/3proxy/3proxy","https://blog.talosintelligence.com/2022/09/lazarus-three-rats.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_pua_3proxy_execution.yml","techniques":["T1572"],"cves":[]},{"id":"f38ce0b9-5e97-4b47-a211-7dc8d8b871da","title":"Potential RDP Tunneling Via Plink","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-04","modified":"2023-01-27","description":"Execution of plink to perform data exfiltration and tunneling","references":["https://www.microsoft.com/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_plink_susp_tunneling.yml","techniques":["T1572"],"cves":[]},{"id":"f7d7ebd5-a016-46e2-9c54-f9932f2d386d","title":"Potential RDP Tunneling Via SSH","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-12","modified":"2023-01-25","description":"Execution of ssh.exe to perform data exfiltration and tunneling through RDP","references":["https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_ssh_rdp_tunneling.yml","techniques":["T1572"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}