Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-09-28
- Updated
- 2026-07-30
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule identifies Windows process creation events where a Visual Studio Code tunnel-related executable is invoked in a way consistent with renaming (e.g., a command line ending in “.exe tunnel” plus expected tunnel arguments and service components). Attackers may abuse VS Code tunneling to establish or relay remote connectivity for command-and-control while blending in with legitimate tooling behavior. The detection relies on process creation telemetry, including Image/ParentImage and CommandLine string patterns for tunnel execution, internal service startup, and cmd.exe-launched parent activity.
Reporting behind it
- ipfyx.frhttps://ipfyx.fr/post/visual-studio-code-tunnel/
- badoption.euhttps://badoption.eu/blog/2023/01/31/code_c2.html
- code.visualstudio.comhttps://code.visualstudio.com/docs/remote/tunnels
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_vscode_tunnel_renamed_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary"
id: 29a4f69d-97f0-48df-a328-9e91cfa319f6
status: test
description: This rule identifies Windows process creation events where a Visual Studio Code tunnel-related executable is invoked in a way consistent with renaming (e.g., a command line ending in “.exe tunnel” plus expected tunnel arguments and service components). Attackers may abuse VS Code tunneling to establish or relay remote connectivity for command-and-control while blending in with legitimate tooling behavior. The detection relies on process creation telemetry, including Image/ParentImage and CommandLine string patterns for tunnel execution, internal service startup, and cmd.exe-launched parent activity.
references:
- https://ipfyx.fr/post/visual-studio-code-tunnel/
- https://badoption.eu/blog/2023/01/31/code_c2.html
- https://code.visualstudio.com/docs/remote/tunnels
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_vscode_tunnel_renamed_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-28
modified: 2025-10-29
tags:
- attack.command-and-control
- attack.t1071.001
- attack.t1219
logsource:
category: process_creation
product: windows
detection:
selection_image_only_tunnel:
OriginalFileName: null
CommandLine|endswith: .exe tunnel
selection_image_tunnel_args:
CommandLine|contains|all:
- .exe tunnel
- --accept-server-license-terms
selection_image_tunnel_service:
CommandLine|contains|all:
- "tunnel "
- service
- internal-run
- tunnel-service.log
selection_parent_tunnel:
ParentCommandLine|endswith: " tunnel"
Image|endswith: \cmd.exe
CommandLine|contains|all:
- "/d /c "
- \servers\Stable-
- code-server.cmd
filter_main_parent_code:
ParentImage|endswith:
- \code-tunnel.exe
- \code.exe
filter_main_image_code:
Image|endswith:
- \code-tunnel.exe
- \code.exe
condition: (1 of selection_image_* and not 1 of filter_main_image_*) or (selection_parent_tunnel and not 1 of filter_main_parent_*)
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 2cf29f11-e356-4f61-98c0-1bdb9393d6da
type: derived