Tailscale
Telemetry Evidence
These values show how indexed rules identify Tailscale telemetry.Kusto
Tailscale_Audit_CL Tailscale_Devices_CL Tailscale_Network_CL Tailscale_Users_CL Panther
Tailscale.Audit tailscale
Detection Rules
Kusto #
- Tailscale Premium: DERP relay traffic surge source low: Identifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale IsRelayed flag, traffic via 127.3.3.40). Operational signal useful for spotting policy drift.
T1572 - Tailscale Premium: Large outbound transfer over tailnet source medium: Identifies when a single src-dst pair transfers more than 100 MB over the tailnet within a 1-hour window. Large bursts can indicate data staging, exfiltration, or a misconfigured backup. Requires Tailscale Premium or Enterprise.
T1020,T1041 - Tailscale Premium: Mass fan-out from single node source high: Identifies when a single node initiates flows to 25 or more unique destinations within a 15-minute window. Sudden fan-out is consistent with port scanning, lateral discovery, or worm-style propagation. Requires Tailscale Premium or Enterprise.
T1018,T1021,T1046 - Tailscale Premium: Network flow beaconing detected source medium: Identifies when flows between a src-dst pair recur at a regular interval (80%+ of inter-flow gaps cluster on the same delta over 10+ flows). Signature of C2 beaconing or scheduled exfiltration. Requires Tailscale Premium or Enterprise.
T1029,T1071,T1095 - Tailscale Premium: New posture integration added source medium: Identifies when a new device-posture integration is added to the tailnet (Jamf, Kandji, Intune, Kolide, Defender for Endpoint, CrowdStrike, SentinelOne). Verify the addition was sanctioned.
T1098 - Tailscale Premium: Posture integration disabled or removed source high: Identifies when a device-posture integration is disabled or removed from the tailnet. Posture integrations enforce device compliance - removal weakens fleet posture and is a possible defense-evasion step.
T1556,T1685 - Tailscale Premium: Subnet router throughput anomaly source low: Identifies when a subnet router (gateway node bridging the tailnet to an on-prem or cloud subnet) handles 3x or more its 7-day baseline traffic in the last hour. Spikes can indicate exfiltration or scanning. Requires Tailscale Premium or Enterprise.
T1041,T1572 - Tailscale Premium: Unexpected exit-node egress source medium: Identifies when a node sends traffic via an exit node not used in the prior 7-day baseline. First-seen exit destinations from a node may indicate routing-policy drift, data exfiltration, or compromise.
T1041,T1090 - Tailscale: Auth key created source low: Identifies when a new Tailscale auth key is generated. Auth keys allow unattended device enrollment into the tailnet - confirm it was expected and revoke if not.
T1098 - Tailscale: Device key expiring within 7 days source medium: Identifies tailnet devices whose machine key expires within the next 7 days and where key expiry is not disabled. Surface proactively so renewal can be scheduled rather than forced during an outage.
T1078
Show 14 more
- Tailscale: Device started advertising subnet routes source medium: Identifies when a tailnet device begins advertising subnet routes (subnet-router capability) not present in the previous snapshot. Unexpected advertisement may indicate a compromised node expanding reachable surface area or an unsanctioned admin change.
T1021,T1556 - Tailscale: Device Tailscale SSH newly enabled source medium: Identifies when Tailscale SSH is enabled on a device that previously did not have it. SSH provides authenticated shell access over the tailnet using Tailscale identity, broadening attack surface if unexpected. Verify and confirm the SSH ACL covers it.
T1021,T1098 - Tailscale: DNS nameservers modified source high: Identifies when the tailnet's global DNS nameserver list is modified. Adding an attacker-controlled resolver as a tailnet-wide nameserver enables broad DNS hijacking for every device using MagicDNS resolution.
T1556,T1568 - Tailscale: Exit node advertised or approved source low: Identifies when a device starts advertising itself as an exit node, or when an admin approves one. Validate the device and operator - rogue exit nodes can intercept tailnet egress.
T1090 - Tailscale: External (shared-in) device added source medium: Identifies new external (shared-in) devices joining the tailnet that were not present in the prior 24-hour baseline. Each shared-in device expands the trust boundary - confirm the share matches a documented agreement and ACL scope.
T1078 - Tailscale: MagicDNS disabled source medium: Identifies when MagicDNS is turned off on the tailnet. Disabling MagicDNS changes DNS behaviour for every device and is occasionally a precursor to wider DNS hijacking - verify the change was intentional.
T1556 - Tailscale: Mass credential revocation in short window source high: Identifies when five or more API keys, OAuth clients, or auth keys are revoked or deleted within one hour. May be routine rotation, or a typical cleanup pattern after credential compromise.
T1070 - Tailscale: New API access token or OAuth client created source medium: Identifies when a new API access token or OAuth client is created in the tailnet. These grant programmatic access - verify the actor and intent.
T1098,T1136 - Tailscale: OAuth client or API key created with write scopes source high: Identifies creation of a Tailscale OAuth client or API access key whose granted scopes include WRITE permissions (anything matching :write). Tokens with write scopes are high-value adversary targets.
T1098,T1136 - Tailscale: Policy file (ACL) modified source medium: Identifies when the tailnet ACL/policy file is modified. Review the diff - incorrect ACLs can silently expand blast radius across the tailnet.
T1556 - Tailscale: Split-DNS configuration modified source high: Identifies when the tailnet split-DNS configuration is modified. Split-DNS overrides per-domain resolution within the tailnet - an attacker adding a new domain mapping or changing the resolver IP can hijack DNS for that domain.
T1556,T1568 - Tailscale: Tailnet lock validation failed source high: Identifies tailnet devices with a non-empty TailnetLockError, indicating the device failed tailnet-lock cryptographic validation. Suspicious - likely an unsigned node attempting to join.
T1078,T1556 - Tailscale: Unauthorized device connected to control plane source high: Identifies devices actively connected to the Tailscale control plane (ConnectedToControl=true) but not yet authorized by an admin (Authorized=false). Often benign onboarding but can indicate rogue joins.
T1078,T1098 - Tailscale: User role elevated to admin or owner source high: Identifies when a user's tailnet role changes from a lower-privilege role to admin, network-admin, or owner between consecutive snapshots. Privilege escalation is a high-value attacker objective and warrants prompt review.
T1078,T1098
Panther #
- Tailscale HTTPS Disabled source high: A Tailscale User disabled HTTPS settings in your organization's tenant.
- Tailscale Machine Approval Requirements Disabled source high: A Tailscale User disabled machine approval requirement settings in your organization's tenant. This means devices can access your network without requiring approval.
- Tailscale Magic DNS Disabled source high: A Tailscale User disabled magic dns settings in your organization's tenant.