Cloudflared Tunnel Execution

 Original Source: [Sigma source]
Title: Cloudflared Tunnel Execution
Status: test
Description:Detects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
References:
  -https://blog.reconinfosec.com/emergence-of-akira-ransomware-group
  -https://github.com/cloudflare/cloudflared
  -https://developers.cloudflare.com/cloudflare-one/connections/connect-apps
Author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-17
modified:2023-12-20
Tags:
  • -'attack.command-and-control'
  • -'attack.t1102'
  • -'attack.t1090'
  • -'attack.t1572'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -' tunnel '
      -' run '

    CommandLine|contains:
      -'-config '
      -'-credentials-contents '
      -'-credentials-file '
      -'-token '

  condition:selection
Falsepositives:
  -Legitimate usage of Cloudflared tunnel.
Level: medium