DNS Resolution to Reverse Tunneling Services (ngrok-style) - T1572/T1090

This rule monitors DNS query logs for connections to common public tunneling and proxy services (such as Cloudflare Tunnel, Ngrok, and others) originating from internal private IP address spaces. These services are frequently abused by adversaries to create unauthorized external access channels (reverse tunnels) into a private network, facilitating command and control or data exfiltration while bypassing firewall restrictions.