Skip to content

Block Visaul Studio Dev Tunnels #179

@Still34

Description

@Still34

Summary

Dev Tunnel has been increasingly getting popular amongst legitimate developers and threat actors alike. Specifically, TAs are installing and running VSCode post-exploitation and establishing Dev Tunnels between the victim and the attacker. It might be a good idea to add blocking Dev Tunnels to the machine hardening list? Microsoft offers a group policy for managing the behavior, so it can probably be added via a registry key.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions