BIOC Informational

Unsigned process makes connections over DNS ports

An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.

Module:
Platform Analytics
Agent event type:
Network
Category:
Exfiltration
Status:
Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Indicator:

Network action type = outgoing , failed AND remote port = 53 Process os parent signature = Unsigned , N/A , Weak Hash , Invalid Signature Host host os = windows

Preventable: yes