Microsoft Dev Tunnels: Tunnelling C2 and More
ID: c2fb79c7-85d7-50a5-8ec3-131d992b4553
STIX ID: report--c2fb79c7-85d7-50a5-8ec3-131d992b4553
Feed Name: On the Hunt
This report explains how attackers can misuse Microsoft Dev Tunnels to hide command-and-control traffic and create persistent remote access (including RDP/SSH) by leveraging legitimate Microsoft domains and tunneling infrastructure. It includes examples of Cobalt Strike configuration, a PowerShell-based persistence technique using GitHub device authentication, recommended detections (process/module, TLS/domain anomalies, loopback RDP brute-force thresholds), memory forensic guidance, and IOCs such as devtunnel executable and DLL hashes and related domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
