For the complete documentation index, see llms.txt. This page is also available as Markdown.

A compromised process accessed a rare external host

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

2 Hours

Deduplication Period

1 Day

Required Data

Requires all of the following: XDR Agent XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

EDR Windows C2 Analytics

ATT&CK Tactic

Command and Control (TA0011)

ATT&CK Technique

Application Layer Protocol (T1071)

Severity

Low

Description

A compromised process accessed a rare external host.

Attacker's Goals

Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.

Investigative actions

  • Investigate the compromised process.

  • Check the rare remote host.

Variations

A process compromised by DLL sideloading accessed a rare external host and transferred a large amount of data

Synopsis

Field
Value

ATT&CK Tactic

Command and Control (TA0011)

ATT&CK Technique

Application Layer Protocol (T1071)

Severity

High

Description

A process compromised by DLL sideloading accessed a rare external host and transferred a large amount of data.

Attacker's Goals

Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.

Investigative actions

  • Investigate the compromised process.

  • Check the rare remote host.

A process compromised by DLL sideloading accessed a rare external host

Synopsis

Field
Value

ATT&CK Tactic

Command and Control (TA0011)

ATT&CK Technique

Application Layer Protocol (T1071)

Severity

Medium

Description

A process compromised by DLL sideloading accessed a rare external host.

Attacker's Goals

Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.

Investigative actions

  • Investigate the compromised process.

  • Check the rare remote host.

An injected process accessed a rare external host

Synopsis

Field
Value

ATT&CK Tactic

Command and Control (TA0011)

ATT&CK Technique

Application Layer Protocol (T1071)

Severity

Medium

Description

An injected process accessed a rare external host.

Attacker's Goals

Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.

Investigative actions

  • Investigate the compromised process.

  • Check the rare remote host.

Was this helpful?