Cloudflared Tunnel Execution

Rule Info

Tags
attack.command_and_control attack.t1090 DEMO attack.t1102 attack.t1572
Name
Cloudflared Tunnel Execution
Id
9a019ffc-3580-4c9d-8d87-079f7e8d3fd4
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
Author
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: add new rules related to cloudflared usage (#4243)
BlueTeamOps
2023-05-18