BIOC Informational

Curl connects to an external network

Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization.

Module:
Platform Analytics
Agent event type:
Network
Category:
Exfiltration
Status:
Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Indicator:

Network action type = outgoing , failed AND remote ip != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND remote port != 53 AND 0 Process initiated by = curl AND cgo signer != *palo alto networks* Host host os = linux , windows

Preventable: yes