RAT

CloudFlare Tunnel

Cloudflare Tunnel (cloudflared) creates outbound-only tunnels from a host to Cloudflare, exposing internal services (RDP, SSH, SMB, HTTP) without inbound firewall rules. In the Swisscom intrusion described by The DFIR Report in June 2026, threat actors installed it as a Windows service on a domain controller for persistence and proxied RDP through it.

Tool overview

Category
RAT
Research authors
Not recorded
Created
2024-08-02
Last modified
2026-10-05
Privileges
User for standalone tunnels; Administrator to install the Windows service (runs as SYSTEM)
Free / availability
Yes
Verification required
No account required for Quick Tunnels; named tunnels require a Cloudflare account for creation and a tunnel token or credentials to run
Supported platforms
LinuxWindowsmacOS

Capabilities

Outbound-only reverse tunnelExposes internal RDP/SSH/SMB/HTTP servicesRuns as a Windows service

Executables & installation paths

Filename
cloudflared.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

cloudflared.exe
C:\Program Files (x86)\cloudflared\cloudflared.exe
C:\Program Files\cloudflared\cloudflared.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\cloudflared\*
Description
Token file written by 'cloudflared service install <TOKEN>' on recent versions (service then runs with --token-file)
OS
Windows
File
C:\Windows\System32\config\systemprofile\.cloudflared\*
Description
Service-context config.yml, cert.pem and <tunnel-id>.json credentials for locally managed tunnels
OS
Windows
File
C:\Users\*\.cloudflared\*
Description
Per-user config.yml, cert.pem and tunnel credentials
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
Cloudflared
Description
Service installation (display name "Cloudflared agent", auto start). ImagePath contains 'tunnel run --token <TOKEN>' on older versions or '--token-file' on newer versions.
EventID
1
ProviderName
Cloudflared
LogFile
Application.evtx
Description
cloudflared registers an event source named Cloudflared and logs "Cloudflared service starting" / "service arguments"

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\Cloudflared
Description
Service key; ImagePath may contain the tunnel token
Path
HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Cloudflared
Description
Event log source registered during service install

FORENSIC EVIDENCE

Network artifacts

Description
Tunnel edge destinations and SNI hostnames (TCP 7844 for HTTP/2; UDP 7844 for QUIC)
Domains
  • region1.v2.argotunnel.com
  • region2.v2.argotunnel.com
  • us-region1.v2.argotunnel.com
  • us-region2.v2.argotunnel.com
  • _v2-origintunneld._tcp.argotunnel.com
  • cftunnel.com
  • h2.cftunnel.com
  • quic.cftunnel.com
Ports
  • 7844
Description
Public DNS routing targets for named tunnels (CNAME targets, not tunnel edge connections)
Domains
  • *.cfargotunnel.com
Ports
Not recorded
Description
Temporary public HTTPS hostnames generated by Quick Tunnels
Domains
  • *.trycloudflare.com
Ports
  • 443
Description
Optional software update checks over HTTPS
Domains
  • update.argotunnel.com
  • api.cloudflare.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
WindowsServiceName
Value
Cloudflared
Type
CommandLine
Value
cloudflared.exe service install <TOKEN>
Type
CommandLine
Value
cloudflared.exe tunnel run --token <TOKEN>
Type
CommandLine
Value
cloudflared.exe tunnel --url http://localhost:8080
Type
RDPArtifact
Value
The Swisscom case reported RDP connections through Cloudflare Tunnel with a loopback source (::%16777216) in Windows event logs; this is a tunneling indicator, not unique to cloudflared

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_processes_sigma.yml
Description
Detects potential processes activity of CloudFlare Tunnel RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_network_sigma.yml
Description
Detects potential network activity of CloudFlare Tunnel RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_files_sigma.yml
Description
Detects potential files activity of CloudFlare Tunnel RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_registry_sigma.yml
Description
Detects potential registry activity of CloudFlare Tunnel RMM tool

References

Acknowledgements

Person
The DFIR Report
Handle
@TheDFIRReport
Person
Swisscom B2B CSIRT
Handle
Not recorded