Cross-source coverage
T1572 / ATT&CK
Protocol Tunneling
76 rules · 75 families across 6 sources.
1562 atomic-IOC hidden · include
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.
Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.
Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogesxi:vpxdesxcli:network
How MITRE says to detect it DET0538
Detection Strategy for Protocol Tunneling accross OS platforms.
Windows Analytic 1483
Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.
WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=1
Linux Analytic 1484
sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.
auditd:SYSCALLsocket/connect calls showing SSH processes forwarding arbitrary portslinux:syslogsshd sessions with unusual port forwarding parameterslinux:osquerysocat, ssh, or nc processes opening unexpected ports
macOS Analytic 1485
launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.
macos:unifiedlogprocess execution of ssh with -L/-R forwarding flagsmacos:unifiedlogencrypted outbound traffic carrying unexpected application data
ESXi Analytic 1486
VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.
esxi:vpxdESXi processes relaying traffic via SSH or unexpected portsesxcli:networklistening sockets bound with non-standard encapsulated protocols
elastic/detection-rules
27 rules| Detection | Severity | Format |
|---|---|---|
| Deprecated - Potential DNS Tunneling via Iodine | High | Elastic TOML |
| Potential Protocol Tunneling via EarthWorm | High | Elastic TOML |
| Potential Remote Desktop Tunneling Detected | High | Elastic TOML |
| Curl SOCKS Proxy Activity from Unusual Parent | Medium | Elastic TOML |
| Curl SOCKS Proxy Detected via Defend for Containers | Medium | Elastic TOML |
| Deprecated - Potential Protocol Tunneling via Chisel Server | Medium | Elastic TOML |
| Port Forwarding Rule Addition | Medium | Elastic TOML |
| Potential DNS Exfiltration via Excessive Chunked Queries | Medium | Elastic TOML |
| Potential DNS Tunneling via NsLookup | Medium | Elastic TOML |
| Potential ICMP Tunneling Activity to the Internet | Medium | Elastic TOML |
+ 17 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
20 rules| Detection | Severity | Format |
|---|---|---|
| Silence.EDA Detection | Critical | Sigma |
| Communication To LocaltoNet Tunneling Service Initiated | High | Sigma |
| Communication To LocaltoNet Tunneling Service Initiated - Linux | High | Sigma |
| Potential RDP Tunneling Via Plink | High | Sigma |
| Potential RDP Tunneling Via SSH | High | Sigma |
| Process Initiated Network Connection To Ngrok Domain | High | Sigma |
| PUA - 3Proxy Execution | High | Sigma |
| PUA - Ngrok Execution | High | Sigma |
| RDP Over Reverse SSH Tunnel | High | Sigma |
| RDP to HTTP or HTTPS Target Ports | High | Sigma |
+ 10 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
10 rules| Detection | Severity | Format |
|---|---|---|
| Cisco IOS XE Tunnel Interface Configuration | Undefined | SPL |
| Linux Ngrok Reverse Proxy Usage | Undefined | SPL |
| Ngrok Reverse Proxy on Network | Undefined | SPL |
| Okta Non-Standard VPN Usage | Undefined | SPL |
| Windows Ngrok Reverse Proxy Usage | Undefined | SPL |
| Windows Potential Cloudflared Network Connection | Undefined | SPL |
| Windows Potential Cloudflared Tunnel Execution | Undefined | SPL |
| Windows Protocol Tunneling with Plink | Undefined | SPL |
| Windows SoftEther VPN Masquerading as Legitimate Binary | Undefined | SPL |
| Windows SSH Proxy Command | Undefined | SPL |
elastic/protections-artifacts
8 rules| Detection | Severity | Format |
|---|---|---|
| Potential Linux Tunneling and/or Port Forwarding | Undefined | Elastic TOML |
| Potential Linux Tunneling or Port Forwarding via SSH | Undefined | Elastic TOML |
| Potential Linux Tunneling via Cloudflared | Undefined | Elastic TOML |
| Potential Network Traffic Tunneling via Proxychains | Undefined | Elastic TOML |
| Potential Protocol Tunneling via Legit Utilities | Undefined | Elastic TOML |
| Potential Remote Desktop Protocol Tunneling | Undefined | Elastic TOML |
| Potential Traffic Tunneling with QEMU | Undefined | Elastic TOML |
| Torsocks Execution | Undefined | Elastic TOML |
socfortress/Wazuh-Rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Cloudflared tunnel usage detected (potential protocol tunneling) | High | Wazuh XML |
| Microsoft Dev Tunnel usage detected (potential protocol tunneling) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · ngrok Tunnel Execution (T1572) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell DoH Beaconing (T1572) | High | Wazuh XML |
| VSCode Remote Tunnel usage detected (potential protocol tunneling) | High | Wazuh XML |
| Generic tunneling command detected (possible protocol tunneling) | Medium | Wazuh XML |
Emerging Threats Open
5 rules| Detection | Severity | Format |
|---|---|---|
| ET INFO Observed DNS over HTTPS Domain (dns4me .net) in TLS SNI | Informational | Suricata |
| ET INFO Observed DNS over HTTPS Domain in TLS SNI (ada .openbld .net) | Informational | Suricata |
| ET INFO Observed DNS over HTTPS Domain in TLS SNI (basic .rethinkdns .com) | Informational | Suricata |
| ET INFO Observed DNS over HTTPS Domain in TLS SNI (ric .openbld .net) | Informational | Suricata |
| ET INFO Observed DNS Query to *.ngrok Domain (ngrok .pro) | Informational | Suricata |