Windows Network Connections to *.devtunnels.ms

Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Kamran Saifullah (SigmaHQ), DRL 1.1
Published
2023-11-20
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule flags network connections initiated by a process where the destination hostname ends with .devtunnels.ms. Such connections can be abused by attackers to establish command-and-control style access, including reverse shells or persistence mechanisms via the DevTunnels infrastructure. It relies on Windows network connection telemetry with fields indicating whether the connection was initiated and the destination hostname.

Related detections9 linkedT1572 — drag to rearrange
Suspicious SCATTERED SPIDER Chisel Tunnel to Cloudflare Quick Tunnel (via process_creation)
Suspicious Cloudflared Tunnel Execution for Command and Control by Kraken Ransomware
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Possible Plink Reverse Tunnel Command Line Execution
Chisel Reverse Tunnel Tool Execution from Temporary Directory
Malicious Anubis Ransomware Cloudflare Tunnel via cloudflared (via process_creation)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Tunneling (via rdp)
Suspicious SSH Reverse Tunnel via Renamed plink Utility on Triofox Host
Windows Network Connections to *.devtunnels.ms
Pivot detection · T1572 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.