ATT&CK T1599 - GRE Tunnel from Untrusted Source

This rule detects the presence of GRE (Generic Routing Encapsulation) tunnel traffic (IP protocol 47) originating from any source IP address to the local network. It triggers an alert if three such GRE packets are observed from the same source within a 60-second window. This could indicate an attempt to establish a GRE tunnel, potentially for defense evasion or to bypass network security controls.