Cloud Atlas PowerCloud PowerShell SSH/Tor Tunnel Persistence
This rule detects potential tunnel creation using PowerShell. It identifies network connections from PowerShell processes to common SSH (22) or Tor (9001, 9050) ports, as well as PowerShell script block activity involving socket connections directed at .onion domains, SSH keys, or authorized keys files, which may indicate remote access tunneling or command-and-control communication.
Splunk (SPL)

