Linux network connections to ngrok tunneling endpoints

Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.

FreeReviewedSigma · High · v3
Product
linux
Category
network_connection
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-11-03
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule identifies executable network connections whose destination hostname contains ngrok tunnel domains across multiple regions. Such communications can indicate attempts to route traffic through an external tunneling service, which may be used to enable data exfiltration or command-and-control infrastructure. It relies on Linux network connection telemetry that includes destination hostname for outgoing connections.

Related detections9 linkedT1572 — drag to rearrange
Windows Executable Initiating Connections to ngrok Tunnel Domains
Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Linux: Network connections initiated to LocaltoNet tunneling subdomains
Windows: Detect cloudflared tunnel cleanup command execution
Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Windows Process Initiated Connections to Ngrok Domains
Malicious Anubis Ransomware Cloudflare Tunnel via cloudflared (via process_creation)
Malicious QEMU Covert Network Tunnel via User-Mode netdev Socket (via process_creation)
Malicious Tunneling Tool Execution on Linux Host (via process_creation)
Linux network connections to ngrok tunneling endpoints
Pivot detection · T1572 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.