Tunneling, Proxying & Network Exposure

Detects reverse tunnels, SOCKS proxies, and tools that expose internal services to the internet

18 rules in tunneling.yml

CRITICAL: 8 | HIGH: 10

Rule IDSeverityTitleDescriptionRefs
chisel_tunnelCRITICALChisel Tunnel ToolInstalls or runs chisel, a tool for creating encrypted TCP/UDP tunnels through firewalls
dnscat2_tunnelCRITICALdnscat2 DNS TunnelInstalls or runs dnscat2, a tool for establishing C2 channels over DNS
frp_tunnelCRITICALFRP Reverse ProxyInstalls or configures frp (fast reverse proxy) for tunneling through firewalls
icmptunnel_tunnelCRITICALICMP TunnelInstalls or runs icmptunnel to tunnel IP traffic over ICMP echo requests
iodine_dns_tunnelCRITICALIodine DNS TunnelInstalls or runs iodine/iodined to tunnel IP traffic over DNS
ligolo_tunnelCRITICALLigolo Tunneling AgentInstalls or runs ligolo-ng, a tunneling tool for pivoting through networks
ngrok_exposureCRITICALngrok Service ExposureInstalls or runs ngrok to expose internal services to the internet
revsocks_tunnelCRITICALReverse SOCKS Proxy ToolInstalls or runs a reverse SOCKS proxy (revsocks, gost, or similar)
bore_tunnelHIGHBore Tunnel ExposureInstalls or runs bore to expose local ports through a public relay
cloudflared_tunnelHIGHCloudflare Tunnel Exposurecloudflared tunnel/access is invoked with –url or –hostname. Cloudflare Tunnels punch through outbound-only firewalls and expose internal services without ingress rules.
localtunnel_exposureHIGHLocalTunnel ExposureInstalls or runs localtunnel (lt) to expose local services to the internet
rathole_tunnelHIGHRathole NAT Traversal TunnelInstalls or runs rathole, a Rust-based reverse proxy for NAT traversal
serveo_tunnelHIGHServeo SSH TunnelUses SSH to expose local services via serveo.net public relay
socat_port_forwardHIGHSocat TCP Port ForwardingUses socat to relay TCP traffic between hosts, potentially forwarding internal services
ssh_remote_forwardHIGHSSH Remote Port ForwardingCreates a remote port forward to expose internal services via an external SSH server
ssh_socks_proxyHIGHSSH SOCKS ProxyCreates a SOCKS proxy via SSH dynamic port forwarding for traffic tunneling
tailscale_unauthorizedHIGHUnauthorized Tailscale SetupInstalls or activates Tailscale which could bypass network security controls
vpn_setup_unauthorizedHIGHUnauthorized VPN SetupInstalls or configures WireGuard, OpenVPN, or other VPN software for unauthorized network access