-
Notifications
You must be signed in to change notification settings - Fork 330
Open
Description
Summary
Dev Tunnel has been increasingly getting popular amongst legitimate developers and threat actors alike. Specifically, TAs are installing and running VSCode post-exploitation and establishing Dev Tunnels between the victim and the attacker. It might be a good idea to add blocking Dev Tunnels to the machine hardening list? Microsoft offers a group policy for managing the behavior, so it can probably be added via a registry key.
References
Metadata
Metadata
Assignees
Labels
No labels