← Back to Explore
sigmamediumHunting
Visual Studio Code Tunnel Remote File Creation
Detects the creation of file by the "node.exe" process in the ".vscode-server" directory. Could be a sign of remote file creation via VsCode tunnel feature
Detection Query
selection:
Image|contains: \servers\Stable-
Image|endswith: \server\node.exe
TargetFilename|contains: \.vscode-server\data\User\History\
condition: selection
Author
Nasreddine Bencherchali (Nextron Systems)
Created
2023-10-25
Data Sources
windowsFile Events
Platforms
windows
References
Tags
attack.command-and-control
Raw Content
title: Visual Studio Code Tunnel Remote File Creation
id: 56e05d41-ce99-4ecd-912d-93f019ee0b71
status: test
description: |
Detects the creation of file by the "node.exe" process in the ".vscode-server" directory. Could be a sign of remote file creation via VsCode tunnel feature
references:
- Internal Research
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-10-25
tags:
- attack.command-and-control
logsource:
category: file_event
product: windows
detection:
selection:
Image|contains: '\servers\Stable-'
Image|endswith: '\server\node.exe'
TargetFilename|contains: '\.vscode-server\data\User\History\'
condition: selection
falsepositives:
- Unknown
level: medium