avatar

D LaB

@DLAB
USACompletionist
0 followers2 downloads9 copies0 likes30 views

2 detections

This rule monitors DNS query logs for connections to common public tunneling and proxy services (such as Cloudflare Tunnel, Ngrok, and others) originating from internal private IP address spaces. These services are frequently abused by adversaries to create unauthorized external access channels (reverse tunnels) into a private network, facilitating command and control or data exfiltration while bypassing firewall restrictions.
avatar
D LaB@DLAB
avatar
Detections.ai Community
28 days ago
5025
Detects the execution of the Cloudflare Tunnel client (cloudflared.exe) on Windows endpoints by monitoring process command line arguments, such as 'tunnel', 'run', or 'proxy-dns'. This tool can be used to establish unauthorized remote access tunnels, potentially bypassing firewall configurations.
avatar
D LaB@DLAB
avatar
Detections.ai Community
28 days ago
405