Abnormal process connection to default Meterpreter port
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Non-Standard Port (T1571)
Severity
Informational
Description
This process has probably been compromised by Meterpreter and is now used by it to run malicious commands.
Attacker's Goals
Run Metasploits's malicious post-exploitation tool named Meterpreter to further compromise the host.
Investigative actions
Verify if the destination IP is running a Metasploit server.
Look for malicious action being done by the suspicious process.
Variations
PreviousAbnormal network communication with a rare combination of HTTP User Agent and HTTP Server
NextAbnormal RDP connections to multiple hosts from a rarely seen host
Was this helpful?
