Renamed Visual Studio Code Tunnel Execution
Description
Detects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
Query · sigma
selection_image_only_tunnel: OriginalFileName: null CommandLine|endswith: .exe tunnel selection_image_tunnel_args: CommandLine|contains|all: - .exe tunnel - --accept-server-license-terms selection_image_tunnel_service: CommandLine|contains|all: - 'tunnel ' - service - internal-run - tunnel-service.log selection_parent_tunnel: ParentCommandLine|endswith: ' tunnel' Image|endswith: \cmd.exe CommandLine|contains|all: - '/d /c ' - \servers\Stable- - code-server.cmd filter_main_parent_code: ParentImage|endswith: - \code-tunnel.exe - \code.exe filter_main_image_code: Image|endswith: - \code-tunnel.exe - \code.exe condition: (1 of selection_image_* and not 1 of filter_main_image_*) or (selection_parent_tunnel and not 1 of filter_main_parent_*)
Known false positives
- Unknown