Suspicious Outbound SMTP Connections
Description
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Query · sigma
selection: DestinationPort: - 25 - 587 - 465 - 2525 Initiated: 'true' filter_clients: Image|endswith: - \thunderbird.exe - \outlook.exe filter_mailserver: Image|startswith: C:\Program Files\Microsoft\Exchange Server\ filter_outlook: Image|startswith: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_ Image|endswith: \HxTsr.exe condition: selection and not 1 of filter_*
Known false positives
- Other SMTP tools