Network Connection Initiated To DevTunnels Domain

 Original Source: [Sigma source]
Title: Network Connection Initiated To DevTunnels Domain
Status: test
Description:Detects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
  -https://blueteamops.medium.com/detecting-dev-tunnels-16f0994dc3e2
  -https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/security
  -https://cydefops.com/devtunnels-unleashed
Author: Kamran Saifullah
Date: 2023-11-20
modified:None
Tags:
  • -'attack.exfiltration'
  • -'attack.command-and-control'
  • -'attack.t1567.001'
  • -'attack.t1572'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationHostname|endswith: '.devtunnels.ms'
  condition:selection
Falsepositives:
  -Legitimate use of Devtunnels will also trigger this.
Level: medium