
D LaB
@DLABUSACompletionist
0 followers2 downloads9 copies0 likes30 views
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Categories
1
1
1
1
Platforms
1
1
Products / Services
1
1
MITRE Techniques
1
1
1
1
This rule monitors DNS query logs for connections to common public tunneling and proxy services (such as Cloudflare Tunnel, Ngrok, and others) originating from internal private IP address spaces. These services are frequently abused by adversaries to create unauthorized external access channels (reverse tunnels) into a private network, facilitating command and control or data exfiltration while bypassing firewall restrictions.
Detects the execution of the Cloudflare Tunnel client (cloudflared.exe) on Windows endpoints by monitoring process command line arguments, such as 'tunnel', 'run', or 'proxy-dns'. This tool can be used to establish unauthorized remote access tunnels, potentially bypassing firewall configurations.
