LoFP LoFP / support engineers and iot operators may run localproxy on field devices or jump hosts that legitimately use aws iot secure tunneling. confirm the host is an approved device-management asset, the parent process and binary path are expected, and the destination mapping points at an authorized local service. allowlist by host, user, or signed install path where that use is documented.

Techniques

Sample rules

Potential Tunneling via AWS IoT Secure Tunneling Localproxy

Description

Identifies AWS IoT Secure Tunneling localproxy started in destination mode that then resolves and connects to the Secure Tunneling data plane, data.tunneling.iot..amazonaws.com, on TCP/443. Destination mode opens no listener; once the operator joins the tunnel the proxy forwards streams to a local service such as SSH on 127.0.0.1:22. Public red-team research shows this signed, documented binary used as post-exploitation C2 that resembles legitimate IoT device management. OpenTunnel and access tokens live in the operator’s AWS account, not the victim’s.

Detection logic

sequence by process.entity_id with maxspan=5m
  [process where event.type == "start" and event.action in ("exec", "exec_event", "start") and
    (
      process.args in ("-d", "--destination-app") or
      (process.args in ("-m", "--mode") and process.args in ("dst", "destination")) or
      process.args like ("--mode=dst", "--mode=destination")
    ) and
    (
      /* Official binary, container image path, or Windows original filename */
      (
        process.name like~ ("localproxy", "localproxy.exe") or
        ?process.pe.original_file_name like~ "localproxy.exe" or
        process.executable like~ "*aws-iot-securetunneling-localproxy*"
      ) or
      /* Renamed binary: dest mode plus AWS region or tunneling endpoint */
      (
        (
          process.args regex """[a-z]{2}(-[a-z]+)+-[0-9]+""" or
          process.args in ("-e", "--proxy-endpoint", "-r", "--region") or
          process.args like~ "*tunneling.iot*"
        ) and
        process.args in (
          "-t", "--access-token",
          "-c", "--capath",
          "-b", "--local-bind-address",
          "-m", "--mode"
        ) and
        not process.name like~ (
          "timeout", "time", "env", "nice", "nohup", "stdbuf",
          "bash", "dash", "sh", "zsh", "sudo", "sshd", "useradd"
        )
      )
    )]
  [network where event.action in ("lookup_requested", "lookup_result") and
    dns.question.name like~ (
      "data.tunneling.iot.*.amazonaws.com",
      "data.tunneling.iot.*.amazonaws.com.cn"
    )]
  [network where event.action == "connection_attempted" and destination.port == 443]