Outbound TLS connection to Microsoft Dev Tunnels (devtunnels.ms) from server-role asset - possible covert C2 tunneling
This rule detects outbound TLS connections from server-role assets to 'devtunnels.ms', a service that facilitates temporary public tunnels to internal services. This behavior is flagged as a potential indicator of unauthorized command-and-control (C2) tunneling, particularly when originating from critical infrastructure like Domain Controllers or Exchange OWA servers.
Suricata

