Visual Studio Code Tunnel Shell Execution — Detection Rule

Detects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.

Read the full analysis on IntelFusions