Cloud Atlas PowerCloud PowerShell SSH/Tor Tunnel Persistence

This rule detects potential tunnel creation using PowerShell. It identifies network connections from PowerShell processes to common SSH (22) or Tor (9001, 9050) ports, as well as PowerShell script block activity involving socket connections directed at .onion domains, SSH keys, or authorized keys files, which may indicate remote access tunneling or command-and-control communication.