{"id":"T1219.001","name":"IDE Tunneling","url":"https://attack.mitre.org/techniques/T1219/001","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0133","stix_id":"x-mitre-detection-strategy--3efcd3e4-9238-4686-990b-27ac110dccfd","name":"IDE Tunneling Detection via Process, File, and Network Behaviors","url":"https://attack.mitre.org/detectionstrategies/DET0133","analytics":[{"id":"AN0375","stix_id":"x-mitre-analytic--e3517ec0-f12a-4f64-8d10-e6bc2677f7d7","name":"Analytic 0375","description":"Detection of the creation of VSCode or JetBrains CLI tunneling profiles followed by persistent remote access via IDE-integrated tunnels, potentially authenticated via GitHub or JetBrains accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0133#AN0375","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Outbound connection to *.tunnels.api.visualstudio.com or *.devtunnels.ms","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Used to define the temporal proximity between tunnel profile creation and outbound connection."},{"field":"TunnelDomainPatterns","description":"Domain patterns for tunnel endpoints may change with IDE versions or organizations."},{"field":"AuthorizedUserList","description":"Helps filter tunnel usage from trusted developer accounts."}],"live":true,"detection_strategies":["DET0133"],"techniques":["T1219.001"]},{"id":"AN0376","stix_id":"x-mitre-analytic--a0a0f8e9-7a55-4450-8569-7a0e1c0aac0b","name":"Analytic 0376","description":"Creation of VSCode tunnel configuration file combined with interactive remote session via code CLI or ssh with JetBrains gateway.","url":"https://attack.mitre.org/detectionstrategies/DET0133#AN0376","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve on code or jetbrains-gateway with remote flags","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open: Write to ~/.vscode-cli/code_tunnel.json","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Connections to *.devtunnels.ms or tunnels.api.visualstudio.com","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PathRegex","description":"Regex patterns for user home directory file paths may vary by distro or user."},{"field":"TunnelCLIFlags","description":"Tunnel flags used by CLI tools can be customized or obfuscated by adversaries."},{"field":"Username","description":"The Linux user account associated with tunnel initiation; may vary across developer environments"},{"field":"TunnelArtifactPath","description":"The filepath to the .vscode-cli/code_tunnel.json file may vary by distribution or IDE version"},{"field":"CommandLineFlags","description":"Different IDEs or wrapper scripts may launch with different tunnel-related CLI options (e.g., --remote, --host)"}],"live":true,"detection_strategies":["DET0133"],"techniques":["T1219.001"]},{"id":"AN0377","stix_id":"x-mitre-analytic--1a93a610-7389-4ea7-a053-e99d35a5477a","name":"Analytic 0377","description":"Detection of JetBrains or VSCode tunnel profile creation followed by unusual persistent SSH or IDE-based tunnel communications to devtunnel APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0133#AN0377","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process: code or jetbrains-gateway launching with --tunnel or --remote","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"creation of ~/.vscode-cli/code_tunnel.json","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"HTTPs connection to tunnels.api.visualstudio.com","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ParentProcessName","description":"Helps scope tunnel launch context to non-interactive or suspicious parent processes."},{"field":"RemoteTunnelPersistence","description":"Allows tracking of tunnel re-establishment across reboots for persistence."},{"field":"RemoteFlag","description":"May include values like --remote, -R, or embedded ssh arguments passed by IDEs"},{"field":"LaunchAgentPath","description":"If the IDE uses persistence via LaunchAgents, defenders may choose where to monitor for tunnel auto-launching"},{"field":"TunnelReconnectInterval","description":"Frequency of retry attempts for tunnel reconnection can affect correlation window"}],"live":true,"detection_strategies":["DET0133"],"techniques":["T1219.001"]}],"live":true,"version":"1.0","techniques":["T1219.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}