A commonly abused process connected to a rare external host
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows C2 Analytics
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol: Web Protocols (T1071.001)
Severity
Low
Description
A commonly abused process connected to a rare external host.
Attacker's Goals
Communicate with the attacker's Command and Control (C2) infrastructure.
Investigative actions
Investigate the actor process connected to the external host.
Get further details about the uncommon external destination.
Assess whether this communication pattern is expected or not.
Variations
PreviousA commonly abused process connected to a rare cloud resource
NextA compiled HTML help file wrote a script file to the disk
Was this helpful?
