Analytics BIOC
Low
✕
Abnormal network communication through TOR using an uncommon port
Suspicious connection from a known TOR IP to an uncommon port.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
Attacker's goals:
Attackers might use TOR IP combined with random ports.to hide C2 inbound communication from inside a host.
Investigative actions:
Investigate the network configuration related to the participating port. Investigate processes that were listening to that port.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Abnormal network communication through TOR using an uncommon port and App-id Low
- Abnormal network communication through TOR using a suspicious port Low