LoFP LoFP / legitimate installation of code-tunnel as a service

Techniques

Sample rules

Visual Studio Code Tunnel Service Installation

Description

Detects the installation of VsCode tunnel (code-tunnel) as a service.

Detection logic

condition: selection
selection:
  CommandLine|contains|all:
  - 'tunnel '
  - service
  - internal-run
  - tunnel-service.log