• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    NightEagle RDP tunneling via Microsoft dev tunnels (devtunnels.ms)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•3

    Detects outbound TLS connections to Microsoft Dev Tunnels (devtunnels.ms), which can be abused for lateral movement or protocol tunneling of services such as RDP to bypass network ingress filtering.

    Suricata

    Tags

    T1572 - Protocol TunnelingT1021.001 - Remote Desktop ProtocolNetwork Connection OutboundNetwork Data TransferRemote Access SessionNetwork GenericSuricata IDSSnort IDSTlsTrojan Activity

    Found in

    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?