Windows Process Initiated Connections to Ngrok Domains

Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.

FreeReviewedSigma · High · v2
Product
windows
Category
network_connection
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-16
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule flags Windows processes that initiate network connections to hostnames ending with common ngrok domain patterns (.ngrok-free.app, .ngrok-free.dev, .ngrok.app, .ngrok.dev, .ngrok.io). Such tunneling services can be abused to support command-and-control or to deliver additional payloads, so these connections are security-relevant even though ngrok can be used legitimately. The detection relies on network_connection telemetry that includes the process initiator and the destination hostname.

Related detections9 linkedT1572 — drag to rearrange
Linux network connections to ngrok tunneling endpoints
Windows Executable Initiating Connections to ngrok Tunnel Domains
Malicious Anubis Ransomware Cloudflare Tunnel via cloudflared (via process_creation)
Windows Process Initiated Connections to .btunnel.co.in Domains
Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Linux: Network connections initiated to LocaltoNet tunneling subdomains
Windows Network Connections to Cloudflared Tunnel Domains
Windows Network Connections to Visual Studio Code Tunnels Domain
Windows Suspicious Non-Browser Network Traffic to api.telegram.org
Windows Process Initiated Connections to Ngrok Domains
Pivot detection · T1572 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.