Analytics BIOC
Informational
✕
Abnormal process connection to default Meterpreter port
This process has probably been compromised by Meterpreter and is now used by it to run malicious commands.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Non-Standard Port (T1571)
Attacker's goals:
Run Metasploits's malicious post-exploitation tool named Meterpreter to further compromise the host.
Investigative actions:
Verify if the destination IP is running a Metasploit server. Look for malicious action being done by the suspicious process.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
1 variation:
- Abnormal process connection to default Meterpreter port on an internet-facing server Low (parent: Informational)