Globally uncommon root-domain port combination by a common process (sha256)
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Global Anomaly Analytics
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol (T1071)
Severity
Informational
Description
A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to.
Attacker's Goals
Attackers may use various methods to execute code from the context of another process to avoid detection.
Investigative actions
Check if the actor process loaded a suspicious DLL before the alert.
Check if the actor process was injected before the alert.
Check if the process execution and connections are legitimate.
Variations
PreviousGlobally uncommon root domain from a signed process
NextGlobally uncommon root-domain port combination from a signed process
Was this helpful?
