Potential Tunneling via AWS IoT Secure Tunneling Localproxy

Last updated 11 days ago on 2026-09-18
Created 11 days ago on 2026-09-18

About

Identifies AWS IoT Secure Tunneling localproxy started in destination mode that then resolves and connects to the Secure Tunneling data plane, data.tunneling.iot.<region>.amazonaws.com, on TCP/443. Destination mode opens no listener; once the operator joins the tunnel the proxy forwards streams to a local service such as SSH on 127.0.0.1:22. Public red-team research shows this signed, documented binary used as post-exploitation C2 that resembles legitimate IoT device management. OpenTunnel and access tokens live in the operator's AWS account, not the victim's.
Tags
Domain: EndpointDomain: NetworkDomain: OT/IoTOS: WindowsOS: LinuxOS: macOSPlatform: WindowsPlatform: LinuxPlatform: macOSPlatform: AWSUse Case: Threat DetectionTactic: Command and ControlData Source: Elastic DefendService: AWS IoTRule Type: Event Correlation (EQL)Language: eql
Severity
high
Risk Score
73
MITRE ATT&CK™

Command and Control (TA0011)(external, opens in a new tab or window)

False Positive Examples
Support engineers and IoT operators may run localproxy on field devices or jump hosts that legitimately use AWS IoT Secure Tunneling. Confirm the host is an approved device-management asset, the parent process and binary path are expected, and the destination mapping points at an authorized local service. Allowlist by host, user, or signed install path where that use is documented.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Event Correlation Rule
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.network-*logs-endpoint.events.process-*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
sequence by process.entity_id with maxspan=5m [process where event.type == "start" and event.action in ("exec", "exec_event", "start") and ( process.args in ("-d", "--destination-app") or (process.args in ("-m", "--mode") and process.args in ("dst", "destination")) or process.args like ("--mode=dst", "--mode=destination") ) and ( /* Official binary, container image path, or Windows original filename */ ( process.name like~ ("localproxy", "localproxy.exe") or ?process.pe.original_file_name like~ "localproxy.exe" or process.executable like~ "*aws-iot-securetunneling-localproxy*" ) or /* Renamed binary: dest mode plus AWS region or tunneling endpoint */ ( ( process.args regex """[a-z]{2}(-[a-z]+)+-[0-9]+""" or process.args in ("-e", "--proxy-endpoint", "-r", "--region") or process.args like~ "*tunneling.iot*" ) and process.args in ( "-t", "--access-token", "-c", "--capath", "-b", "--local-bind-address", "-m", "--mode" ) and not process.name like~ ( "timeout", "time", "env", "nice", "nohup", "stdbuf", "bash", "dash", "sh", "zsh", "sudo", "sshd", "useradd" ) ) )] [network where event.action in ("lookup_requested", "lookup_result") and dns.question.name like~ ( "data.tunneling.iot.*.amazonaws.com", "data.tunneling.iot.*.amazonaws.com.cn" )] [network where event.action == "connection_attempted" and destination.port == 443]

Install detection rules in Elastic Security

Detect Potential Tunneling via AWS IoT Secure Tunneling Localproxy in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).