Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution

Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-13
Updated
2026-07-30

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule identifies execution of the Chisel tunneling utility on Windows by matching process creation events where the image ends with \chisel.exe. It further looks for command-line arguments consistent with tunneling/client-server operation, including SOCKS5 and reverse tunneling parameters and common address forms. Attackers may use tunneling tools like Chisel to proxy traffic and bypass direct network access controls, so correlating these process and command-line patterns can reveal suspicious command-and-control behavior. Telemetry relies on Windows process creation logs with the image path and full command line.

Related detections9 linkedT1090.001 — drag to rearrange
Malicious SOCKS Proxy Tunnel via Earthworm Rssocks by UAT-8837
Malicious Volt Typhoon Port Proxy Configuration via Netsh (via process_creation)
Suspicious netsh Port Proxy Configuration for Covert Tunneling
Malicious Port Forwarding Tunnel via Netsh Portproxy (via process_creation)
Windows Execution of cloudflared for Cloudflare Try/Quick Tunnel Ad-hoc Tunneling
Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Windows execution of cloudflared.exe from a non-default directory
Windows SharpChisel Command-Line Execution via SharpChisel.exe
Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Pivot detection · T1090.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.