Cloudflared Covert C2 Tunnel Deployed via PowerShell as Windows Service
Detects the unauthorized installation and execution of cloudflared (a Cloudflare Tunnel binary). This rule monitors for PowerShell-based downloading of the binary, silent installation via msiexec, service installation commands, and cloudflared execution from unexpected parent processes, which are patterns often associated with adversary lateral movement or establishing persistence.
Cortex XDR

