Title:Network Connection Initiated To BTunnels Domains Status:test Description:Detects network connections to BTunnels domains initiated by a process on the system.
Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References: -https://defr0ggy.github.io/research/Utilizing-BTunnel-For-Data-Exfiltration/ Author: Kamran Saifullah Date: 2024-09-13 modified:None Tags:
-'attack.exfiltration'
-'attack.command-and-control'
-'attack.t1567'
-'attack.t1572'
Logsource:
category: network_connection
product: windows
Detection: selection: Initiated:
'true' DestinationHostname|endswith:
'.btunnel.co.in' condition:selection Falsepositives:
-Legitimate use of BTunnels will also trigger this. Level:medium