
Summary
Identifies the use of tailscaled to potentially tunnel network traffic. This rule detects process creation events for tailscaled or tailscaled.exe with command-line arguments that enable a SOCKS5 server or outbound HTTP proxy listening, which can be used to route or conceal traffic from network monitoring. It targets endpoints across Windows, Linux, and macOS, leveraging data sources such as process start events from various EDR/log platforms (Endgame, CrowdStrike, Sysmon) and Windows Security Logs. The technique maps to MITRE ATT&CK: T1090 (Proxy), T1219 (Remote Access Tools), and T1572 (Protocol Tunneling) under the Command and Control tactic (TA0011). By focusing on the specific tailscaled invocation and known proxy/listen flags, the rule aims to surface legitimate tailscaled usage that could be repurposed for covert tunneling or evasion of network controls. Cross-platform applicability and integration with multiple data sources enhance coverage for endpoint environments and support faster detection when tailscaled is used to establish external tunneling channels or bypass restrictions.
Categories
- Endpoint
- Windows
- Linux
- macOS
Data Sources
- Process
ATT&CK Techniques
- T1090
- T1219
- T1572
Created: 2026-07-29