Uncommon Linux process communication to a rare external host
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Abnormal Communication Analytics
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol (T1071)
Severity
Informational
Description
An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server.
Attacker's Goals
Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.
Investigative actions
Identify the process contacting the remote domain and determine whether the traffic is malicious.
Look for other endpoints on your network that are alsocontacting the suspicious domain.
Inspect the domain or URL for suspicious indicators or its presence in malicious reputation lists.
Variations
Was this helpful?
