Cloudflared Tunnel Connections Cleanup
Nasreddine Bencherchali (Nextron Systems)
Detects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
attack.command_and_control attack.t1102 attack.t1090 attack.t1572 DEMO
Link to Public Repo