Analytics BIOC Low

Rare communication over email ports to external email server by unsigned process

These methods are used by malware and attackers to leak data and remain undetected.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Non-Application Layer Protocol (T1095)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:

Attackers might use well-known email ports as a C&C channel to evade detection and firewall rules.

Investigative actions:

Check whether the initiator process is benign or normal for the host and/or user performing it. Check whether additional malicious commands were executed from the same process.

Test period:
N/A (single event)
Deduplication:
1 Hour