VPN and Tunneling Tool Activity Detection

Detects the use of VPN clients, tunneling tools (like Tor, ngrok, plink, and SSH port forwarding), and network proxy configurations on endpoints. The rule monitors for known VPN process execution, network connections to VPN provider domains, unauthorized tunnel protocol activity, and Windows registry-based proxy modifications.