Cloudflared Tunnel Connections Cleanup

Rule Info

Tags
attack.command_and_control attack.t1090 DEMO attack.t1102 attack.t1572
Name
Cloudflared Tunnel Connections Cleanup
Id
7050bba1-1aed-454e-8f73-3f46f09ce56a
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: add new rules related to cloudflared usage (#4243)
BlueTeamOps
2023-05-18