Cross-source coverage

T1572 / ATT&CK

Protocol Tunneling

74 rules · 73 families across 6 sources.

2 deprecated hidden · include 1351 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.

Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.

Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.

Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogesxi:vpxdesxcli:network

How MITRE says to detect it DET0538

Detection Strategy for Protocol Tunneling accross OS platforms.

Windows Analytic 1483

Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.

  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 1484

sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.

  • auditd:SYSCALL socket/connect calls showing SSH processes forwarding arbitrary ports
  • linux:syslog sshd sessions with unusual port forwarding parameters
  • linux:osquery socat, ssh, or nc processes opening unexpected ports

macOS Analytic 1485

launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.

  • macos:unifiedlog process execution of ssh with -L/-R forwarding flags
  • macos:unifiedlog encrypted outbound traffic carrying unexpected application data

ESXi Analytic 1486

VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.

  • esxi:vpxd ESXi processes relaying traffic via SSH or unexpected ports
  • esxcli:network listening sockets bound with non-standard encapsulated protocols

elastic/detection-rules

25 rules
Detection Severity Format
Potential Protocol Tunneling via EarthWorm High Elastic TOML
Potential Remote Desktop Tunneling Detected High Elastic TOML
Curl SOCKS Proxy Activity from Unusual Parent Medium Elastic TOML
Curl SOCKS Proxy Detected via Defend for Containers Medium Elastic TOML
Port Forwarding Rule Addition Medium Elastic TOML
Potential DNS Exfiltration via Excessive Chunked Queries Medium Elastic TOML
Potential DNS Tunneling via NsLookup Medium Elastic TOML
Potential ICMP Tunneling Activity to the Internet Medium Elastic TOML
Potential Linux Tunneling and/or Port Forwarding Medium Elastic TOML
Potential Linux Tunneling and/or Port Forwarding via Command Line Medium Elastic TOML

+ 15 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

20 rules
Detection Severity Format
Silence.EDA Detection Critical Sigma
Communication To LocaltoNet Tunneling Service Initiated High Sigma
Communication To LocaltoNet Tunneling Service Initiated - Linux High Sigma
Potential RDP Tunneling Via Plink High Sigma
Potential RDP Tunneling Via SSH High Sigma
Process Initiated Network Connection To Ngrok Domain High Sigma
PUA - 3Proxy Execution High Sigma
PUA - Ngrok Execution High Sigma
RDP Over Reverse SSH Tunnel High Sigma
RDP to HTTP or HTTPS Target Ports High Sigma

+ 10 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

10 rules
Detection Severity Format
Cisco IOS XE Tunnel Interface Configuration Undefined SPL
Linux Ngrok Reverse Proxy Usage Undefined SPL
Ngrok Reverse Proxy on Network Undefined SPL
Okta Non-Standard VPN Usage Undefined SPL
Windows Ngrok Reverse Proxy Usage Undefined SPL
Windows Potential Cloudflared Network Connection Undefined SPL
Windows Potential Cloudflared Tunnel Execution Undefined SPL
Windows Protocol Tunneling with Plink Undefined SPL
Windows SoftEther VPN Masquerading as Legitimate Binary Undefined SPL
Windows SSH Proxy Command Undefined SPL

elastic/protections-artifacts

8 rules
Detection Severity Format
Potential Linux Tunneling and/or Port Forwarding Undefined Elastic TOML
Potential Linux Tunneling or Port Forwarding via SSH Undefined Elastic TOML
Potential Linux Tunneling via Cloudflared Undefined Elastic TOML
Potential Network Traffic Tunneling via Proxychains Undefined Elastic TOML
Potential Protocol Tunneling via Legit Utilities Undefined Elastic TOML
Potential Remote Desktop Protocol Tunneling Undefined Elastic TOML
Potential Traffic Tunneling with QEMU Undefined Elastic TOML
Torsocks Execution Undefined Elastic TOML

socfortress/Wazuh-Rules

6 rules
Detection Severity Format
Cloudflared tunnel usage detected (potential protocol tunneling) High Wazuh XML
Microsoft Dev Tunnel usage detected (potential protocol tunneling) High Wazuh XML
Sysmon - Event 1: Process creation · ngrok Tunnel Execution (T1572) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell DoH Beaconing (T1572) High Wazuh XML
VSCode Remote Tunnel usage detected (potential protocol tunneling) High Wazuh XML
Generic tunneling command detected (possible protocol tunneling) Medium Wazuh XML

Emerging Threats Open

5 rules
Detection Severity Format
ET INFO Observed DNS over HTTPS Domain (dns4me .net) in TLS SNI Informational Suricata
ET INFO Observed DNS over HTTPS Domain in TLS SNI (ada .openbld .net) Informational Suricata
ET INFO Observed DNS over HTTPS Domain in TLS SNI (basic .rethinkdns .com) Informational Suricata
ET INFO Observed DNS over HTTPS Domain in TLS SNI (ric .openbld .net) Informational Suricata
ET INFO Observed DNS Query to *.ngrok Domain (ngrok .pro) Informational Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.