Tunneling, Proxying & Network Exposure
Detects reverse tunnels, SOCKS proxies, and tools that expose internal services to the internet
18 rules in tunneling.yml
CRITICAL: 8 | HIGH: 10
| Rule ID | Severity | Title | Description | Refs |
|---|---|---|---|---|
chisel_ | CRITICAL | Chisel Tunnel Tool | Installs or runs chisel, a tool for creating encrypted TCP/UDP tunnels through firewalls | |
dnscat2_ | CRITICAL | dnscat2 DNS Tunnel | Installs or runs dnscat2, a tool for establishing C2 channels over DNS | |
frp_ | CRITICAL | FRP Reverse Proxy | Installs or configures frp (fast reverse proxy) for tunneling through firewalls | |
icmptunnel_ | CRITICAL | ICMP Tunnel | Installs or runs icmptunnel to tunnel IP traffic over ICMP echo requests | |
iodine_ | CRITICAL | Iodine DNS Tunnel | Installs or runs iodine/iodined to tunnel IP traffic over DNS | |
ligolo_ | CRITICAL | Ligolo Tunneling Agent | Installs or runs ligolo-ng, a tunneling tool for pivoting through networks | |
ngrok_ | CRITICAL | ngrok Service Exposure | Installs or runs ngrok to expose internal services to the internet | |
revsocks_ | CRITICAL | Reverse SOCKS Proxy Tool | Installs or runs a reverse SOCKS proxy (revsocks, gost, or similar) | |
bore_ | HIGH | Bore Tunnel Exposure | Installs or runs bore to expose local ports through a public relay | |
cloudflared_ | HIGH | Cloudflare Tunnel Exposure | cloudflared tunnel/access is invoked with –url or –hostname. Cloudflare Tunnels punch through outbound-only firewalls and expose internal services without ingress rules. | |
localtunnel_ | HIGH | LocalTunnel Exposure | Installs or runs localtunnel (lt) to expose local services to the internet | |
rathole_ | HIGH | Rathole NAT Traversal Tunnel | Installs or runs rathole, a Rust-based reverse proxy for NAT traversal | |
serveo_ | HIGH | Serveo SSH Tunnel | Uses SSH to expose local services via serveo.net public relay | |
socat_ | HIGH | Socat TCP Port Forwarding | Uses socat to relay TCP traffic between hosts, potentially forwarding internal services | |
ssh_ | HIGH | SSH Remote Port Forwarding | Creates a remote port forward to expose internal services via an external SSH server | |
ssh_ | HIGH | SSH SOCKS Proxy | Creates a SOCKS proxy via SSH dynamic port forwarding for traffic tunneling | |
tailscale_ | HIGH | Unauthorized Tailscale Setup | Installs or activates Tailscale which could bypass network security controls | |
vpn_ | HIGH | Unauthorized VPN Setup | Installs or configures WireGuard, OpenVPN, or other VPN software for unauthorized network access |