Ngrok Reverse Tunnel Without Installation - Linux

Rule Info

Name
Ngrok Reverse Tunnel Without Installation - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the usage of ngrok reverse tunnel via SSH without installation of ngrok, which could be used to expose internal services to the internet. Adversaries may use ngrok to create reverse tunnels to bypass network restrictions and facilitate lateral movement or data exfiltration.
Date
2025-10-15 00:00:00
Modified
None
Id
339ef212-6713-4d0e-b2f4-8812b764cb3a
Tags
attack.exfiltration attack.command-and-control attack.t1567 attack.t1568.002 attack.t1572 attack.t1090 attack.t1102 attack.s0508
Type
Nextron Sigma feed only (private)

Rule History