Communication To LocaltoNet Tunneling Service Initiated

 Original Source: [Sigma source]
Title: Communication To LocaltoNet Tunneling Service Initiated
Status: test
Description:Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
References:
  -https://localtonet.com/documents/supported-tunnels
  -https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications
Author: Andreas Braathen (mnemonic.io)
Date: 2024-06-17
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1572'
  • -'attack.t1090'
  • -'attack.t1102'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    DestinationHostname|endswith:
      -'.localto.net'
      -'.localtonet.com'

    Initiated: 'true'
  condition:selection
Falsepositives:
  -Legitimate use of the LocaltoNet service.
Level: high