Analytics BIOC Informational

A process connected to a rare external host

A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071)
Attacker's goals:

Beacon to C2 server and/or exfiltrate data.

Investigative actions:

Check whether the process was injected or otherwise subverted for malicious use.

Test period:
N/A (single event)
Deduplication:
1 Day
6 variations:
  • MSBuild process connected to a rare external host High (parent: Informational) Adds Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)
  • MSBuild process connected to a rare external host Medium (parent: Informational) Adds Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)
  • LOLBIN spawned by an Office executable connected to a rare external host High (parent: Informational)
  • A curl process connected to a rare external host Informational
  • VSCode extension process connected to a rare external host Low (parent: Informational)
  • UNIX LOLBIN process connected to a rare external host Low (parent: Informational)