Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
11 detections
Filters
Last updated
All Time
Detection languages
5
5
1
Contributors
11
Categories
10
7
4
2
2
Platforms
11
Products / Services
10,411
9,526
6,520
4,398
3,688
MITRE Techniques
5
3
3
2
2
IDS Classtypes
1
IDS Protocols
1
Detects cloudflared launched with 'tunnel --url' against localhost or api.trycloudflare.com without managed-tunnel authentication flags, indicating deployment of an ad-hoc Cloudflare Quick Tunnel exposing a local service to the internet.
Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
Detects cloudflared launched with 'tunnel --url' against localhost or api.trycloudflare.com without managed-tunnel authentication flags, indicating deployment of an ad-hoc Cloudflare Quick Tunnel exposing a local service to the internet.
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
Reverse Tunnel Traffic to localhost.run lhr.life Subdomain
