Analytics BIOC
Informational
✕
A process connected to a rare external host
A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Attacker's goals:
Beacon to C2 server and/or exfiltrate data.
Investigative actions:
Check whether the process was injected or otherwise subverted for malicious use.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
6 variations:
- MSBuild process connected to a rare external host High (parent: Informational) Adds Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)
- MSBuild process connected to a rare external host Medium (parent: Informational) Adds Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)
- LOLBIN spawned by an Office executable connected to a rare external host High (parent: Informational)
- A curl process connected to a rare external host Informational
- VSCode extension process connected to a rare external host Low (parent: Informational)
- UNIX LOLBIN process connected to a rare external host Low (parent: Informational)