Windows Network Connections to Cloudflared Tunnel Domains

Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-05-27
Updated
2026-07-31

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule matches outbound network connections from a Windows host to Cloudflared tunnel-related domains when a connection is initiated by a local process. Such activity can indicate misuse of tunnel services to route command-and-control or enable remote access techniques like reverse shells. It relies on network connection telemetry containing the initiated flag and the destination hostname, specifically suffixes for Cloudflared tunnel domains.

Related detections9 linkedT1572 — drag to rearrange
Windows Process Initiated Connections to .btunnel.co.in Domains
Windows Network Connections to Visual Studio Code Tunnels Domain
Linux network connections to ngrok tunneling endpoints
Windows Executable Initiating Connections to ngrok Tunnel Domains
Windows Process Initiated Connections to Ngrok Domains
Suspicious SCATTERED SPIDER Chisel Tunnel to Cloudflare Quick Tunnel (via process_creation)
Suspicious Cloudflared Tunnel Execution for Command and Control by Kraken Ransomware
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Possible Plink Reverse Tunnel Command Line Execution
Windows Network Connections to Cloudflared Tunnel Domains
Pivot detection · T1572 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.