Protocol Tunneling T1572

Tactic: Command & Control

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Events covered

22 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 96 rules share fields, values, and exclusions.

Fields filtered most (67 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine33contains 18, regex_match 11, in 5, wildcard 1(?i)(\-\-dns)?((\s+)|(\=))?((server\=)|(host\=))?((\d{1,3..., (?i)(tcp\s+(139|445|3389|5985|5986))|(\.exe\s+|(authtoken..., (?i)\-(L|R|N|D|C)|IdentitiesOnly=yes|StrictHostKeyChecking=no|ssh, *http*, \d{1,5}:\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d{1,5}
process_name30eq 21, in 8, regex_match 5, starts_with 3, ne 1(?i)ngrok\.exe, 3proxy, chisel, proxychains, (?i)^ssh\.exe
event.type26eq 26start, change
process.args23eq 17, in 7, starts_with 7, contains 6, wildcard 5, regex_match 4, ends_with 1-l, --listen, --preproxy, --proxy, --remote
EventType22eq 12, in 10exec, ProcessRollup2, exec_event, start, connection_attempted
EventID18eq 17, in 11, 4688, 4104, 17, 18
host.os.type18eq 17, in 1
Image11ends_with 9, eq 1, is_not_null 1\plink.exe, \ssh.exe, \svchost.exe, ?:\windows\system32\openssh\ssh.exe, \3proxy.exe
DestinationHostname9ends_with 7, contains 2.localto.net, .localtonet.com, tunnel.ap.ngrok.com, tunnel.au.ngrok.com, tunnel.eu.ngrok.com
Initiated9eq 9true
parent_process_name6in 5, eq 1, starts_with 1, wildcard 1bash, csh, ash, *.sh, .
OriginalFileName5eq 5plink, cloudflared.exe, curl.exe, plink.exe, vpnbridge*.exe
QueryName5ends_with 2, contains 1, in 1, is_not_null 1, regex_match 1*.ngrok.com, *.ngrok.io, .devtunnels.ms, .v2.argotunnel.com, [0-9]{1,5}-[a-za-z0-9+/=]{15,63}\..+
Type5eq 5
process.args_count5ge 54, 3, 6

Top indicator values (524 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
251078
EventTypeeq
exec
9576
EventTypein
ProcessRollup2
9117
EventTypein
exec
9201
EventTypein
exec_event
9149
EventTypein
start
9163
EventTypein
executed
598
EventTypein
process_started
583
Initiatedeq
true
950
EventIDeq
1
6241
EventIDeq
4688
5317
EventIDeq
4104
4269
parent_process_namein
bash
565
parent_process_namein
csh
539
parent_process_namein
dash
542
parent_process_namein
fish
540
parent_process_namein
ksh
540
parent_process_namein
sh
565
parent_process_namein
tcsh
540
parent_process_namein
zsh
563
CommandLinecontains
connect=
44
CommandLinecontains
restrict=off
44
CommandLinecontains
:3389
34
CommandLinecontains
tunnel
36
process.argseq
-l
417
process.argseq
-s
48
process.argseq
tunnel
46
process.argsstarts_with
-R
44
process.args_countge
4
48
CommandLinein
*http*
33

Exclusions (220 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagein
/usr/bin/podman
2
ParentCommandLineeq
runc init
2
ParentImagewildcard
/home/linuxbrew/.linuxbrew/caskroom/codex/*/codex-x86_64-unknown-linux-musl
2
dest_ipcidr_match
10.0.0.0/8
2
dest_ipcidr_match
127.0.0.0/8
2
dest_ipcidr_match
169.254.0.0/16
2
dest_ipcidr_match
172.16.0.0/12
2
dest_ipcidr_match
192.168.0.0/16
2
dest_ipin
10.0.0.0/8
2
dest_ipin
100.64.0.0/10
2
dest_ipin
127.0.0.0/8
2
dest_ipin
169.254.0.0/16
2
dest_ipin
172.16.0.0/12
2
dest_ipin
192.0.0.0/24
2
dest_ipin
192.0.0.0/29
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 27 rules

Elastic 33 rules

Splunk 26 rules

Kusto 10 rules