Visual Studio Code Tunnel Shell Execution

 Original Source: [Sigma source]
Title: Visual Studio Code Tunnel Shell Execution
Status: test
Description:Detects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
References:
  -https://ipfyx.fr/post/visual-studio-code-tunnel/
  -https://badoption.eu/blog/2023/01/31/code_c2.html
  -https://code.visualstudio.com/docs/remote/tunnels
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-10-25
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1071.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|contains: '\servers\Stable-'
    ParentImage|endswith: '\server\node.exe'
    ParentCommandLine|contains: '.vscode-server'
  selection_child_1:
    Image|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains: '\terminal\browser\media\shellIntegration.ps1'
  selection_child_2:
    Image|endswith:
      -'\wsl.exe'
      -'\bash.exe'

  condition:selection_parent and 1 of selection_child_*
Falsepositives:
  -Legitimate use of Visual Studio Code tunnel and running code from there
Level: medium