Unauthorized TOR Usage
STATUS: CLOSED / COMPLETE
ANALYST: Erick Cisneros Ruballos
DATETIME: Apr 26, 2025
A structured threat hunting investigation to detect unauthorized TOR browser usage within an enterprise Windows environment, demonstrating real SOC workflows and detection techniques.
Executive Summary
Management suspects that some employees may be using TOR browsers to bypass network security controls due to anomalous encrypted traffic patterns and connections to known TOR entry nodes. There have also been anonymous internal reports of employees seeking to access restricted sites.
The investigation confirmed that user "erick" on the "ec-win2" device successfully downloaded, silently installed, and launched the TOR browser. Extensive connections to the TOR network were established, and evidence of documentation ("tor-shopping-list.txt") was identified on the user's desktop, marking a definitive Acceptable Use Policy violation.
Investigation Timeline
File Download
User "erick" downloaded the tor-browser-windows portable executable to the Downloads folder.
Silent Execution
The user executed the downloaded binary in silent mode (/S), initiating a background installation of the TOR Browser.
Browser Launch
User opened the TOR browser. Subsequent processes associated with TOR browser (firefox.exe, tor.exe) were created.
C2 / Proxy Connection
A network connection to IP 111.69.37.214 on port 9001 was established using tor.exe from the desktop.
Network Tunneling
Multiple successful connections detected, including local connections to 127.0.0.1 on port 9150 and external 443.
Artifact Creation
The user created a file named "tor-shopping-list.txt" on the desktop, indicating documentation of their TOR activities.
Indicators of Compromise (IOCs)
| TOR Entry Node | 111.69.37.214:9001 |
| Local Proxy | 127.0.0.1:9150 |
| Installer Native | tor-browser-windows-x86_64-portable-14.5.exe |
| Core Tor Binary | tor.exe |
| Evidence File | tor-shopping-list.txt |
KQL Threat Hunt Validation
DeviceFileEvents
| where DeviceName == "ec-win2"
| where InitiatingProcessAccountName == "erick"
| where FileName contains "tor"
| where Timestamp >= datetime(2025-04-26T18:41:13.036Z)
| sort by Timestamp desc
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, SHA256DeviceProcessEvents
| where DeviceName == "ec-win2"
| where ProcessCommandLine contains "tor-browser-windows-x86_64-portable-14.5.exe"
| project Timestamp, DeviceName, AccountName, ActionType, ProcessCommandLineDeviceProcessEvents
| where DeviceName == "ec-win2"
| where FileName has_any ("tor.exe","firefox.exe", "tor-browser.exe")
| project Timestamp, DeviceName, AccountName, ActionType, ProcessCommandLine
| order by Timestamp descDeviceNetworkEvents
| where DeviceName == "ec-win2"
| where InitiatingProcessAccountName != "system"
| where InitiatingProcessFileName in ("tor.exe","firefox.exe")
| where RemotePort in ("9001","9030","9040","9050","9051", "9150", "80", "443")
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileNameStrategic Recommendations
- 1TOR usage was confirmed on the endpoint (ec-win2) by the user (erick).
- 2The device must be isolated from the primary corporate network immediately to prevent potential data exfiltration over the TOR proxy.
- 3The user's direct manager and HR should be notified of the Acceptable Use Policy violation regarding evasion of security boundaries.
- 4Update Endpoint DLP policies to aggressively alert and block the execution footprints of portable Tor browser installations.