1200KM / detection
T1572 Protocol Tunneling — Detection Rules
Detection workspace for T1572 Protocol Tunneling: 23 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Communication To LocaltoNet Tunneling Service Initiated - Linux · test · high · {"category":"network_connection","product":"linux"}
- Communication To Ngrok Tunneling Service - Linux · test · high · {"product":"linux","category":"network_connection"}
- Cloudflared Tunnels Related DNS Requests · test · medium · {"category":"dns_query","product":"windows"}
- DNS Query To Devtunnels Domain · test · medium · {"category":"dns_query","product":"windows"}
- Network Connection Initiated To BTunnels Domains · test · medium · {"category":"network_connection","product":"windows"}
- Network Connection Initiated To Cloudflared Tunnels Domains · test · medium · {"category":"network_connection","product":"windows"}
- Network Connection Initiated To DevTunnels Domain · test · medium · {"category":"network_connection","product":"windows"}
- Communication To LocaltoNet Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Process Initiated Network Connection To Ngrok Domain · test · high · {"category":"network_connection","product":"windows"}
- Communication To Ngrok Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Network Connection Initiated To Visual Studio Code Tunnels Domain · test · medium · {"category":"network_connection","product":"windows"}
- RDP Over Reverse SSH Tunnel · test · high · {"category":"network_connection","product":"windows"}
- RDP to HTTP or HTTPS Target Ports · test · high · {"category":"network_connection","product":"windows"}
- Silence.EDA Detection · test · critical · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Cloudflared Tunnel Connections Cleanup · test · medium · {"category":"process_creation","product":"windows"}
- Cloudflared Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Plink Port Forwarding · test · high · {"category":"process_creation","product":"windows"}
- Potential RDP Tunneling Via Plink · test · high · {"category":"process_creation","product":"windows"}
- PUA - 3Proxy Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Ngrok Execution · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Usage Of Qemu · test · medium · {"category":"process_creation","product":"windows"}
- Port Forwarding Activity Via SSH.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential RDP Tunneling Via SSH · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1572 Protocol Tunneling
MATCH(tunneling_protocol_signature OR disallowed_protocol_over_allowed_port) -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0538 Detection Strategy for Protocol Tunneling accross OS platforms.
AN1483 Analytic 1483
Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.
AN1484 Analytic 1484
sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.
AN1485 Analytic 1485
launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.
AN1486 Analytic 1486
VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.