Command and Control (TA0011)(external, opens in a new tab or window)
text code block:sequence by process.entity_id with maxspan=5m [process where event.type == "start" and event.action in ("exec", "exec_event", "start") and ( process.args in ("-d", "--destination-app") or (process.args in ("-m", "--mode") and process.args in ("dst", "destination")) or process.args like ("--mode=dst", "--mode=destination") ) and ( /* Official binary, container image path, or Windows original filename */ ( process.name like~ ("localproxy", "localproxy.exe") or ?process.pe.original_file_name like~ "localproxy.exe" or process.executable like~ "*aws-iot-securetunneling-localproxy*" ) or /* Renamed binary: dest mode plus AWS region or tunneling endpoint */ ( ( process.args regex """[a-z]{2}(-[a-z]+)+-[0-9]+""" or process.args in ("-e", "--proxy-endpoint", "-r", "--region") or process.args like~ "*tunneling.iot*" ) and process.args in ( "-t", "--access-token", "-c", "--capath", "-b", "--local-bind-address", "-m", "--mode" ) and not process.name like~ ( "timeout", "time", "env", "nice", "nohup", "stdbuf", "bash", "dash", "sh", "zsh", "sudo", "sshd", "useradd" ) ) )] [network where event.action in ("lookup_requested", "lookup_result") and dns.question.name like~ ( "data.tunneling.iot.*.amazonaws.com", "data.tunneling.iot.*.amazonaws.com.cn" )] [network where event.action == "connection_attempted" and destination.port == 443]
Install detection rules in Elastic Security
Detect Potential Tunneling via AWS IoT Secure Tunneling Localproxy in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).