Suspicious ngrok Tunnel Setup via Authtoken or Service Install (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-07
Updated
2026-10-07

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects ngrok being configured with an authtoken or installed as a persistent service which attackers leveraging trusted relationships use to establish durable covert tunnels into the victim network.

Related detections9 linkedT1543.003 — drag to rearrange
Malicious SSH Reverse Tunnel with Hidden Key Path (via process_creation)
Malicious BYOVD Driver Service Creation aswSP_ArPot2 via Process Creation
Suspicious Service Persistence WinSystemHost via Process Creation
Suspicious wlbsctrl.dll Sideloading via IKEEXT Service
Suspicious adhapl Service DLL Dropped in System32 by BellaCPP
Malicious FortiGateUpdate Service DLL Registration by Cyber Partisans (via registry_set)
Suspicious Service Creation Hosting Binary via Svchost (via process_creation)
Malicious Snatch Ransomware SuperBackupMan SafeBoot Service Registration
Suspicious MeshAgent Spawning Command Interpreter (via process_creation)
Suspicious ngrok Tunnel Setup via Authtoken or Service Install (via process_creation)
Pivot detection · T1543.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.