
Rule Info
Tags
attack.command_and_control attack.t1090 DEMO attack.t1102 attack.t1572
Name
Cloudflared Tunnel Execution
Id
9a019ffc-3580-4c9d-8d87-079f7e8d3fd4
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
Author
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule
Link to Public Repo
Rule History
Title
Author
Commit
Date