Analytics BIOC
Low
✕
Rare communication over email ports to external email server by unsigned process
These methods are used by malware and attackers to leak data and remain undetected.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Non-Application Layer Protocol (T1095)
Detector tags: EDR Windows C2 Analytics
Attacker's goals:
Attackers might use well-known email ports as a C&C channel to evade detection and firewall rules.
Investigative actions:
Check whether the initiator process is benign or normal for the host and/or user performing it. Check whether additional malicious commands were executed from the same process.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour