Globally uncommon IP address connection from a signed process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Global Anomaly Analytics
ATT&CK Tactic
Stealth (TA0005), Command and Control (TA0011)
ATT&CK Technique
System Binary Proxy Execution (T1218), Application Layer Protocol (T1071)
Severity
Informational
Description
A signed process connected to an external IP address that, on a global level, it usually doesn't connect to.
Attacker's Goals
Attackers may use various methods to execute code in the context of a signed process to avoid detection.
Investigative actions
Verify the destination IP address reputation.
Check whether the actor process loaded a suspicious DLL before the alert.
Check if the actor process was injected before the alert.
Verify whether the process execution and connections are legitimate.
Variations
Was this helpful?
