Protocol Tunneling T1572

Tactic: Command & Control

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Events covered

22 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 97 rules share fields, values, and exclusions.

Fields filtered most (75 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine33contains 18, regex_match 11, in 5, wildcard 1(?i)(\-\-dns)?((\s+)|(\=))?((server\=)|(host\=))?((\d{1,3..., (?i)(tcp\s+(139|445|3389|5985|5986))|(\.exe\s+|(authtoken..., (?i)\-(L|R|N|D|C)|IdentitiesOnly=yes|StrictHostKeyChecking=no|ssh, *http*, \d{1,5}:\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d{1,5}
process_name30eq 21, in 8, regex_match 5, starts_with 3, ne 1(?i)ngrok\.exe, 3proxy, chisel, proxychains, (?i)^ssh\.exe
event.type26eq 26start, change
EventType23eq 12, in 10, is_null 1exec, ProcessRollup2, exec_event, start, connection_attempted
process.args23eq 17, in 7, starts_with 7, contains 6, wildcard 5, regex_match 4, ends_with 1-l, --listen, --preproxy, --proxy, --remote
EventID18eq 17, in 11, 4688, 4104, 17, 18
host.os.type18eq 17, in 1
Image11ends_with 9, eq 1, is_not_null 1\plink.exe, \ssh.exe, \svchost.exe, ?:\windows\system32\openssh\ssh.exe, \3proxy.exe
DestinationHostname9ends_with 7, contains 2.localto.net, .localtonet.com, tunnel.ap.ngrok.com, tunnel.au.ngrok.com, tunnel.eu.ngrok.com
Initiated9eq 9true
QueryName6ends_with 2, is_not_null 2, contains 1, in 1, regex_match 1*.ngrok.com, *.ngrok.io, .devtunnels.ms, .v2.argotunnel.com, [0-9]{1,5}-[a-za-z0-9+/=]{15,63}\..+
parent_process_name6in 5, eq 1, starts_with 1, wildcard 1bash, csh, ash, *.sh, .
OriginalFileName5eq 5plink, cloudflared.exe, curl.exe, plink.exe, vpnbridge*.exe
Type5eq 5
process.args_count5ge 54, 3, 6

Top indicator values (533 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
251087
EventTypeeq
exec
9579
EventTypein
ProcessRollup2
9118
EventTypein
exec
9206
EventTypein
exec_event
9150
EventTypein
start
9168
EventTypein
executed
598
EventTypein
process_started
583
Initiatedeq
true
950
EventIDeq
1
6242
EventIDeq
4688
5317
EventIDeq
4104
4269
parent_process_namein
bash
566
parent_process_namein
csh
540
parent_process_namein
dash
543
parent_process_namein
fish
541
parent_process_namein
ksh
541
parent_process_namein
sh
566
parent_process_namein
tcsh
541
parent_process_namein
zsh
564
CommandLinecontains
connect=
44
CommandLinecontains
restrict=off
44
CommandLinecontains
:3389
34
CommandLinecontains
tunnel
36
process.argseq
-l
417
process.argseq
-s
48
process.argseq
tunnel
46
process.argsstarts_with
-R
44
process.args_countge
4
48
CommandLinein
*http*
33

Exclusions (244 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
3
dest_ipcidr_match
127.0.0.0/8
3
dest_ipcidr_match
169.254.0.0/16
3
dest_ipcidr_match
172.16.0.0/12
3
dest_ipcidr_match
192.168.0.0/16
3
Imagein
/usr/bin/podman
2
ParentCommandLineeq
runc init
2
ParentImagewildcard
/home/linuxbrew/.linuxbrew/caskroom/codex/*/codex-x86_64-unknown-linux-musl
2
CommandLinecontains
-blockdev
1
CommandLinecontains
-cdrom
1
CommandLinecontains
type=virt
1
CommandLinecontains
ansible
1
CurrentDirectorycontains
ansible
1
CurrentDirectoryeq
/app/ai-test-generation
1
CurrentDirectoryeq
/builds/qa/ai-test-runner
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 27 rules

Elastic 34 rules

Splunk 26 rules

Kusto 10 rules