Cloudflared Tunnels Related DNS Requests

 Original Source: [Sigma source]
Title: Cloudflared Tunnels Related DNS Requests
Status: test
Description:Detects DNS requests to Cloudflared tunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
  -https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-12-20
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1071.001'
  • -'attack.t1572'
Logsource:
  • category: dns_query
  • product: windows
Detection:
  selection:
    QueryName|endswith:
      -'.v2.argotunnel.com'
      -'protocol-v2.argotunnel.com'
      -'trycloudflare.com'
      -'update.argotunnel.com'

  condition:selection
Falsepositives:
  -Legitimate use of cloudflare tunnels will also trigger this.
Level: medium