LoFP LoFP / administrative activity using a remote port forwarding to a local port

Techniques

Sample rules

Port Forwarding Activity Via SSH.EXE

Description

Detects port forwarding activity via SSH.exe

Detection logic

condition: selection
selection:
  CommandLine|contains|windash: ' -R '
  Image|endswith: \ssh.exe

Description

Detects suspicious Plink tunnel port forwarding to a local port

Detection logic

condition: selection
selection:
  CommandLine|contains: ' -R '
  Description: Command-line SSH, Telnet, and Rlogin client