Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Palo Alto Networks Url Logs
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol (T1071)
Severity
Informational
Description
A process made a connection to an external IP address or host that is rarely connected to by the organization.
Attacker's Goals
Connect to a server to retrieve commands or exfiltrate data.
Investigative actions
Check whether the process was injected or otherwise subverted for malicious use.
Variations
PreviousRare communication over email ports to external email server by unsigned process
NextRare DCOM RPC activity
Was this helpful?
