Rare communication over email ports to external email server by unsigned process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent
Detector Tags
EDR Windows C2 Analytics
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Non-Application Layer Protocol (T1095)
Severity
Low
Description
These methods are used by malware and attackers to leak data and remain undetected.
Attacker's Goals
Attackers might use well-known email ports as a C&C channel to evade detection and firewall rules.
Investigative actions
Check whether the initiator process is benign or normal for the host and/or user performing it.
Check whether additional malicious commands were executed from the same process.
PreviousRare binary connected to a rare external host
NextRare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol
Was this helpful?
