Best Detection of 2026 Series: Unauthorized Cloudflared Tunnel Execution for Covert C2
This rule detects the execution of the Cloudflare 'cloudflared' utility from non-standard directory locations. Cloudflared is often abused by threat actors to establish reverse tunnels (e.g., TryCloudflare) to gain unauthorized, persistent, and encrypted external access to a compromised host, effectively bypassing standard perimeter network security controls.
Cortex XDR

