Erick Cisneros
ContactResume
Directory
Overview
Experience
Investigations & Tooling
The Trophy Case
Education
Contact Me
Direct Inquiries
Back to Security Investigations & Tooling
INC-2025-TOR01

Unauthorized TOR Usage

STATUS: CLOSED / COMPLETE

ANALYST: Erick Cisneros Ruballos

DATETIME: Apr 26, 2025

A structured threat hunting investigation to detect unauthorized TOR browser usage within an enterprise Windows environment, demonstrating real SOC workflows and detection techniques.

Threat HuntingMDEKQLWindows 10Acceptable Use Policy
See Full Report on GitHubView Event Creation
Tor Logo with crosshair
Case Brief

Executive Summary

Management suspects that some employees may be using TOR browsers to bypass network security controls due to anomalous encrypted traffic patterns and connections to known TOR entry nodes. There have also been anonymous internal reports of employees seeking to access restricted sites.

The investigation confirmed that user "erick" on the "ec-win2" device successfully downloaded, silently installed, and launched the TOR browser. Extensive connections to the TOR network were established, and evidence of documentation ("tor-shopping-list.txt") was identified on the user's desktop, marking a definitive Acceptable Use Policy violation.

CLASSIFICATIONHIGH SEVERITY
TARGET ASSETec-win2
ORIGIN GEOInternal
COMPROMISED ADerick
Event Chronology

Investigation Timeline

PHASE 12025-04-26T18:41:13Z

File Download

User "erick" downloaded the tor-browser-windows portable executable to the Downloads folder.

C:\Users\erick\Downloads\tor-browser-windows-x86_64-portable-14.5.exe
PHASE 22025-04-26T18:43:57Z

Silent Execution

The user executed the downloaded binary in silent mode (/S), initiating a background installation of the TOR Browser.

C:\Users\erick\Downloads\tor-browser...exe /S
PHASE 32025-04-26T18:47:55Z

Browser Launch

User opened the TOR browser. Subsequent processes associated with TOR browser (firefox.exe, tor.exe) were created.

C:\Users\erick\Desktop\Tor Browser\...\tor.exe
PHASE 42025-04-26T18:48:13Z

C2 / Proxy Connection

A network connection to IP 111.69.37.214 on port 9001 was established using tor.exe from the desktop.

Remote IP: 111.69.37.214:9001
PHASE 52025-04-26T18:48:30Z

Network Tunneling

Multiple successful connections detected, including local connections to 127.0.0.1 on port 9150 and external 443.

Local IP: 127.0.0.1:9150
PHASE 62025-04-26T18:51:13Z

Artifact Creation

The user created a file named "tor-shopping-list.txt" on the desktop, indicating documentation of their TOR activities.

C:\Users\erick\Desktop\tor-shopping-list.txt
Threat Intelligence

Indicators of Compromise (IOCs)

Network Infrastructure
TOR Entry Node111.69.37.214:9001
Local Proxy127.0.0.1:9150
Filesystem & Payloads
Installer Nativetor-browser-windows-x86_64-portable-14.5.exe
Core Tor Binarytor.exe
Evidence Filetor-shopping-list.txt
Telemetry Reconstruction

KQL Threat Hunt Validation

Flag 1: Initial File Download Detection
KQL Query
DeviceFileEvents
| where DeviceName == "ec-win2"
| where InitiatingProcessAccountName == "erick"
| where FileName contains "tor"
| where Timestamp >= datetime(2025-04-26T18:41:13.036Z)
| sort by Timestamp desc
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, SHA256
Flag 2: Suspicious Process Execution
KQL Query
DeviceProcessEvents
| where DeviceName == "ec-win2"
| where ProcessCommandLine contains "tor-browser-windows-x86_64-portable-14.5.exe"
| project Timestamp, DeviceName, AccountName, ActionType, ProcessCommandLine
Flag 3: Tor Service Spin-up
KQL Query
DeviceProcessEvents
| where DeviceName == "ec-win2"
| where FileName has_any ("tor.exe","firefox.exe", "tor-browser.exe")
| project Timestamp, DeviceName, AccountName, ActionType, ProcessCommandLine
| order by Timestamp desc
Flag 4: Outbound Network Egress
KQL Query
DeviceNetworkEvents
| where DeviceName == "ec-win2"
| where InitiatingProcessAccountName != "system"
| where InitiatingProcessFileName in ("tor.exe","firefox.exe")
| where RemotePort in ("9001","9030","9040","9050","9051", "9150", "80", "443")
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName

Strategic Recommendations

  • 1TOR usage was confirmed on the endpoint (ec-win2) by the user (erick).
  • 2The device must be isolated from the primary corporate network immediately to prevent potential data exfiltration over the TOR proxy.
  • 3The user's direct manager and HR should be notified of the Acceptable Use Policy violation regarding evasion of security boundaries.
  • 4Update Endpoint DLP policies to aggressively alert and block the execution footprints of portable Tor browser installations.
© 2026 Erick Cisneros Ruballos
LinkedIn•GitHub•Direct Email