BIOC
Informational
✕
Unsigned process makes connections over DNS ports
An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.
- Module:
- Platform Analytics
- Agent event type:
- Network
- Category:
- Exfiltration
- Status:
- Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Indicator:
Network action type = outgoing , failed AND remote port = 53 Process os parent signature = Unsigned , N/A , Weak Hash , Invalid Signature Host host os = windows
Preventable: yes