Analytics BIOC Low

Uncommon routing table listing via route.exe

The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: System Network Configuration Discovery (T1016)
Attacker's goals:

Attackers can attempt to use the command to discover remote systems they could compromise.

Investigative actions:

Check whether the command line executed is benign or normal for the host and/or user performing it (e.g. an IT script).

Test period:
N/A (single event)
Deduplication:
1 Hour