Network Connection Initiated To BTunnels Domains

Rule Info

Name
Network Connection Initiated To BTunnels Domains
Author
Kamran Saifullah
Description
Detects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
Date
2024-09-13 00:00:00
Modified
None
Id
9e02c8ec-02b9-43e8-81eb-34a475ba7965
Tags
attack.exfiltration attack.t1567.001 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Kamran Saifullah
Merge PR #5003 from @deFr0ggy - Add `Network Connection Initiated To BTunnels Domains`
2024-09-13