LoFP LoFP / t1572

t1572

TitleTags
administrative activity
administrative activity using a remote port forwarding to a local port
another tool that uses the command line switches of ngrok
cdn, cloud load-balancer, software-update, and telemetry hostnames can be long and change often. recursive resolvers, forwarders, nat gateways, and localhost dns listeners can also combine queries from many endpoints under one client address. validate the apex domain and whether the source is an endpoint before treating the activity as tunneling.
dns domains that use large numbers of child domains, such as software or content distribution networks, can trigger this alert and such parent domains can be excluded.
legitimate usage of cloudflared tunnel.
legitimate usage of cloudflared.
legitimate use of btunnels will also trigger this.
legitimate use of cloudflare tunnels will also trigger this.
legitimate use of devtunnels will also trigger this.
legitimate use of ngrok
legitimate use of the localtonet service.
legitimate use of the ngrok service.
legitimate use of visual studio code tunnel will also trigger this.
newly deployed legitimate site-to-site or client vpn gateways, or established gateways that were inactive for more than 5 days, will generate an alert when first observed. where these peers are expected, their external destination ip addresses can be excluded.
ngrok http 3978 (https://learn.microsoft.com/en-us/azure/bot-service/bot-service-debug-channel-ngrok?view=azure-bot-service-4.0)
normal use of iodine is uncommon apart from security testing and research. use by non-security engineers is very uncommon.
there is a potential for false positives if socks proxies are used for legitimate purposes, such as debugging or troubleshooting, or if the \"curl\" command-line tool is used to download files from a known benign source. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
unknown