Windows Process Initiated Connections to .btunnel.co.in Domains

Flags initiated outbound connections to .btunnel.co.in domains from a Windows host.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Kamran Saifullah (SigmaHQ), DRL 1.1
Published
2024-09-13
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule identifies network connections initiated by a local process to destinations ending with .btunnel.co.in on Windows. Such outbound tunneling domains can be abused to support command-and-control behaviors like remote access, reverse shells, or persistence. The detection relies on network connection telemetry that includes whether the connection was initiated and the destination hostname.

Related detections9 linkedT1572 — drag to rearrange
Windows Network Connections to Cloudflared Tunnel Domains
Windows Network Connections to Visual Studio Code Tunnels Domain
Linux network connections to ngrok tunneling endpoints
Windows Executable Initiating Connections to ngrok Tunnel Domains
Windows Process Initiated Connections to Ngrok Domains
Suspicious SCATTERED SPIDER Chisel Tunnel to Cloudflare Quick Tunnel (via process_creation)
Suspicious Cloudflared Tunnel Execution for Command and Control by Kraken Ransomware
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Possible Plink Reverse Tunnel Command Line Execution
Windows Process Initiated Connections to .btunnel.co.in Domains
Pivot detection · T1572 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.