Windows Network Connections to Visual Studio Code Tunnels Domain

Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Kamran Saifullah (SigmaHQ), DRL 1.1
Published
2023-11-20
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule flags outbound network connections initiated by a process where the destination hostname ends with .tunnels.api.visualstudio.com. Such connections may indicate use of Visual Studio Code tunneling, which attackers could potentially leverage for command-and-control style access or persistence. Telemetry required includes Windows network connection events with destination hostname and an initiated-connection indicator.

Related detections9 linkedT1572 — drag to rearrange
Windows Process Initiated Connections to .btunnel.co.in Domains
Windows Network Connections to Cloudflared Tunnel Domains
Linux network connections to ngrok tunneling endpoints
Windows Executable Initiating Connections to ngrok Tunnel Domains
Windows Process Initiated Connections to Ngrok Domains
Suspicious SCATTERED SPIDER Chisel Tunnel to Cloudflare Quick Tunnel (via process_creation)
Suspicious Cloudflared Tunnel Execution for Command and Control by Kraken Ransomware
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Possible Plink Reverse Tunnel Command Line Execution
Windows Network Connections to Visual Studio Code Tunnels Domain
Pivot detection · T1572 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.