LoFP LoFP / t1572

t1572

TitleTags
administrative activity
administrative activity using a remote port forwarding to a local port
another tool that uses the command line switches of ngrok
dns domains that use large numbers of child domains, such as software or content distribution networks, can trigger this alert and such parent domains can be excluded.
legitimate site-to-site or client vpns that use ipsec nat traversal will establish outbound tunnels on udp port 4500. where these tunnels are expected, the internal source hosts or external vpn gateway ip addresses can be excluded. requiring both the source and destination port to be 4500 already removes alerts caused by an external server coincidentally replying to an ephemeral udp source port of 4500.
legitimate usage of cloudflared tunnel.
legitimate usage of cloudflared.
legitimate use of btunnels will also trigger this.
legitimate use of cloudflare tunnels will also trigger this.
legitimate use of devtunnels will also trigger this.
legitimate use of ngrok
legitimate use of the localtonet service.
legitimate use of the ngrok service.
legitimate use of visual studio code tunnel will also trigger this.
ngrok http 3978 (https://learn.microsoft.com/en-us/azure/bot-service/bot-service-debug-channel-ngrok?view=azure-bot-service-4.0)
normal use of iodine is uncommon apart from security testing and research. use by non-security engineers is very uncommon.
there is a potential for false positives if socks proxies are used for legitimate purposes, such as debugging or troubleshooting, or if the \"curl\" command-line tool is used to download files from a known benign source. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
unknown