SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

Create net_connection_win_cloudflared_tunnels #4863

Closed deFr0ggy closed 1 month ago

deFr0ggy commented 1 month ago

Adding rule for detecting Cloudflare Tunnels abuse.

Changelog

update: Cloudflared Tunnels Related DNS Requests - Update description and related field new: Network Connection Initiated To Cloudflared Tunnels Domains

deFr0ggy commented 1 month ago

Article at below.

https://defr0ggy.github.io/research/Abusing-Cloudflared-A-Proxy-Service-To-Host-Share-Applications/