PUA - Fast Reverse Proxy (FRP) Execution

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the use of Fast Reverse Proxy. frp is a fast reverse proxy to help you expose a local server behind a NAT or firewall to the Internet.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Process started" AND PROCESSNAME endswith "\frpc.exe,\frps.exe" OR COMMANDLINE contains "\frpc.ini" OR HASHES contains "MD5=7D9C233B8C9E3F0EA290D2B84593C842,SHA1=06DDC9280E1F1810677935A2477012960905942F,SHA256=57B0936B8D336D8E981C169466A15A5FD21A7D5A2C7DAF62D5E142EE860E387C" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

frack113, Florian Roth