Chisel/Ngrok/FRP Reverse Tunnel Tool Execution or C2 Network Activity

Detects the execution and network activity of known reverse tunneling and proxy tools such as Chisel, Ngrok, and FRP. These tools are commonly abused by adversaries to establish persistence, bypass firewalls, and facilitate command and control (C2) communication. The rule monitors for specific process names, command-line arguments, and DNS requests related to these services.