Tag
medium
advisory
IPSEC NAT Traversal Port Activity Used for Command and Control
1 rule 3 TTPsA detection rule identifies suspicious outbound IPSEC NAT Traversal (NAT-T) tunnels, characterized by UDP traffic where both source and destination ports are 4500, originating from an internal host to an external destination, a technique frequently abused by threat actors to establish covert command and control channels or exfiltrate data while evading network defenses.
command-and-control
network
vpn
exfiltration
protocol-tunneling
1r
3t
medium
advisory
Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling
3 rules 2 TTPs 1 IOCAdversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.
Cloudflare Tunnel
command-and-control
protocol-tunneling
windows
3r
2t
1i