Suspicious TCP Tunnel Via PowerShell Script — Detection Rule

Detects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity

Read the full analysis on IntelFusions