Communication To Ngrok Tunneling Service - Linux

 Original Source: [Sigma source]
Title: Communication To Ngrok Tunneling Service - Linux
Status: test
Description:Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
References:
  -https://twitter.com/hakluke/status/1587733971814977537/photo/1
  -https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent
Author: Florian Roth (Nextron Systems)
Date: 2022-11-03
modified:None
Tags:
  • -'attack.exfiltration'
  • -'attack.command-and-control'
  • -'attack.t1567'
  • -'attack.t1568.002'
  • -'attack.t1572'
  • -'attack.t1090'
  • -'attack.t1102'
  • -'attack.s0508'
Logsource:
  • product: linux
  • category: network_connection
Detection:
  selection:
    DestinationHostname|contains:
      -'tunnel.us.ngrok.com'
      -'tunnel.eu.ngrok.com'
      -'tunnel.ap.ngrok.com'
      -'tunnel.au.ngrok.com'
      -'tunnel.sa.ngrok.com'
      -'tunnel.jp.ngrok.com'
      -'tunnel.in.ngrok.com'

  condition:selection
Falsepositives:
  -Legitimate use of ngrok
Level: high