Analytics Low

A compromised process accessed a rare external host

A compromised process accessed a rare external host.

Module:
Platform Analytics
Data source:
XDR Agent, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:

Communicate with the attacker's Command and Control (C2) infrastructure while leveraging a compromised process to evade detection.

Investigative actions:

Investigate the compromised process. Check the rare remote host.

Test period:
2 Hours
Deduplication:
1 Day
3 variations:
  • A process compromised by DLL sideloading accessed a rare external host and transferred a large amount of data High (parent: Low)
  • A process compromised by DLL sideloading accessed a rare external host Medium (parent: Low)
  • An injected process accessed a rare external host Medium (parent: Low)