Analytics
Low
✕
A compromised process accessed a rare external host
A compromised process accessed a rare external host.
- Module:
- Platform Analytics
- Data source:
- XDR Agent, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:
Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.
Investigative actions:
Investigate the compromised process. Check the rare remote host.
- Test period:
- 2 Hours
- Deduplication:
- 1 Day
3 variations:
- A process compromised by DLL sideloading accessed a rare external host and transferred a large amount of data High (parent: Low)
- A process compromised by DLL sideloading accessed a rare external host Medium (parent: Low)
- An injected process accessed a rare external host Medium (parent: Low)