DNS Query To Devtunnels Domain

 Original Source: [Sigma source]
Title: DNS Query To Devtunnels Domain
Status: test
Description:Detects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
  -https://blueteamops.medium.com/detecting-dev-tunnels-16f0994dc3e2
  -https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/security
  -https://cydefops.com/devtunnels-unleashed
Author: citron_ninja
Date: 2023-10-25
modified:2023-11-20
Tags:
  • -'attack.command-and-control'
  • -'attack.t1071.001'
  • -'attack.t1572'
Logsource:
  • category: dns_query
  • product: windows
Detection:
  selection:
    QueryName|endswith: '.devtunnels.ms'
  condition:selection
Falsepositives:
  -Legitimate use of Devtunnels will also trigger this.
Level: medium