Network Connection Initiated To BTunnels Domains

 Original Source: [Sigma source]
Title: Network Connection Initiated To BTunnels Domains
Status: test
Description:Detects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
  -https://defr0ggy.github.io/research/Utilizing-BTunnel-For-Data-Exfiltration/
Author: Kamran Saifullah
Date: 2024-09-13
modified:None
Tags:
  • -'attack.exfiltration'
  • -'attack.command-and-control'
  • -'attack.t1567'
  • -'attack.t1572'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationHostname|endswith: '.btunnel.co.in'
  condition:selection
Falsepositives:
  -Legitimate use of BTunnels will also trigger this.
Level: medium