Suspicious Plink SSH Tunnel Used for Data Exfiltration

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-05
Updated
2026-08-28

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects the PuTTY plink client invoked with port forwarding and non-interactive SSH options consistent with tunneling and exfiltration. Microsoft observed Marbled Dust using plink to exfiltrate collected data over SSH from Output Messenger victims. Command-line SSH tunneling by an espionage actor over an encrypted channel is used to bypass egress monitoring, so this pattern warrants investigation.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.