Uncommon recurring rare external host access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
14 Days
Required Data
XDR Agent
Detector Tags
Abnormal Communication Analytics
ATT&CK Tactic
Command and Control (TA0011), Exfiltration (TA0010)
ATT&CK Technique
Application Layer Protocol (T1071), Exfiltration Over C2 Channel (T1041), Remote Access Tools (T1219)
Severity
Informational
Description
A process has established recurring connections to an uncommon external host.
Attacker's Goals
Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines. Additionally, establish command and control channels for remote malware control, conduct discovery activities to gather information about the target environment, or exfiltrate sensitive data from compromised systems.
Investigative actions
Identify the process contacting the remote host and determine whether the traffic is malicious.
Look for other endpoints on your network that are also periodically contacting the same external host.
Inspect the domain or URL for malicious indicators or its presence in threat intelligence feeds and reputation lists.
Variations
Was this helpful?
