LOLBAS Network Connection On Uncommon Port


Description

The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports. It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication. This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trusted Windows binaries. Join this detection with the Process Execution events to provide context and avoid false positives.

Query · spl

| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Network_Traffic.All_Traffic where

All_Traffic.app IN (
    "*\\bitsadmin.exe",
    "*\\certutil.exe",
    "*\\cmstp.exe",
    "*\\cscript.exe",
    "*\\ftp.exe",
    "*\\hh.exe",
    "*\\ie4uinit.exe",
    "*\\ieexec.exe",
    "*\\msbuild.exe",
    "*\\msdt.exe",
    "*\\mshta.exe",
    "*\\msiexec.exe",
    "*\\presentationhost.exe",
    "*\\settingsynchost.exe",
    "*\\syncappvpublishingserver.exe",
    "*\\workfolders.exe",
    "*\\wscript.exe",
    "*\\wuauclt.exe"
    )

NOT All_Traffic.dest_ip IN (
        "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
        "100.64.0.0/10", "127.0.0.0/8", "169.254.0.0/16",
        "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32",
        "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32",
        "192.0.0.171/32", "192.0.2.0/24", "192.31.196.0/24",
        "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
        "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24",
        "203.0.113.0/24", "240.0.0.0/4"
    )

NOT (
        (
            All_Traffic.app IN (
                "*\\cscript.exe",
                "*\\wscript.exe"
            )
            All_Traffic.dest_port IN ("80", "443", "3128")
        )
        OR
        (
            All_Traffic.app="*\\ftp.exe"
            All_Traffic.dest_port IN ("20", "21", "989", "990")
        )
        OR
        (
            All_Traffic.app IN (
                "*\\bitsadmin.exe",
                "*\\certutil.exe",
                "*\\cmstp.exe",
                "*\\hh.exe",
                "*\\ieexec.exe",
                "*\\msbuild.exe",
                "*\\msdt.exe",
                "*\\mshta.exe",
                "*\\msiexec.exe",
                "*\\presentationhost.exe",
                "*\\settingsynchost.exe",
                "*\\syncappvpublishingserver.exe",
                "*\\workfolders.exe",
                "*\\wuauclt.exe"
            )
            All_Traffic.dest_port IN ("80", "443")
        )
        OR
        (
            All_Traffic.app IN (
                "*\\certutil.exe",
                "*\\ie4uinit.exe"
            )
            All_Traffic.dest_port IN ("389")
        )
    )

by All_Traffic.action All_Traffic.app All_Traffic.dest
   All_Traffic.dest_ip All_Traffic.dest_port
   All_Traffic.direction All_Traffic.dvc All_Traffic.protocol
   All_Traffic.protocol_version All_Traffic.src
   All_Traffic.src_ip All_Traffic.src_port
   All_Traffic.transport All_Traffic.user
   All_Traffic.vendor_product

| `drop_dm_object_name(All_Traffic)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `lolbas_network_connection_on_uncommon_port_filter`

Implementation guide

To successfully implement this detection you must ingest events into the Network Traffic data model that contain the source, destination, destination port, and communicating process name in the app field. Sysmon EventID 3 is a common source for this data when normalized into the Network Traffic data model.

Known false positives

  • Legitimate software installation, support tooling, scripting, synchronization, or update workflows may still use uncommon ports in some environments. Tune approved destinations, ports, and process paths with the analytic filter macro.

Analyst notes

Known false positives: Legitimate software installation, support tooling, scripting, synchronization, or update workflows may still use uncommon ports in some environments. Tune approved destinations, ports, and process paths with the analytic filter macro.

Raw source LOLBAS Network Connection On Uncommon Port · SPL
Esc
Published by splunk/security_content ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
name: LOLBAS Network Connection On Uncommon Port
id: a6628e6d-be28-4278-b17d-6b5a32968eea
version: 1
creation_date: '2026-08-24'
modification_date: '2026-08-24'
author: Steven Dick, Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
description: |
    The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports.
    It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.
    This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trusted Windows binaries.
    Join this detection with the Process Execution events to provide context and avoid false positives.
data_source:
    - Sysmon EventID 3
search: |
    | tstats `security_content_summariesonly`
      count min(_time) as firstTime
            max(_time) as lastTime

    from datamodel=Network_Traffic.All_Traffic where

    All_Traffic.app IN (
        "*\\bitsadmin.exe",
        "*\\certutil.exe",
        "*\\cmstp.exe",
        "*\\cscript.exe",
        "*\\ftp.exe",
        "*\\hh.exe",
        "*\\ie4uinit.exe",
        "*\\ieexec.exe",
        "*\\msbuild.exe",
        "*\\msdt.exe",
        "*\\mshta.exe",
        "*\\msiexec.exe",
        "*\\presentationhost.exe",
        "*\\settingsynchost.exe",
        "*\\syncappvpublishingserver.exe",
        "*\\workfolders.exe",
        "*\\wscript.exe",
        "*\\wuauclt.exe"
        )

    NOT All_Traffic.dest_ip IN (
            "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
            "100.64.0.0/10", "127.0.0.0/8", "169.254.0.0/16",
            "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32",
            "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32",
            "192.0.0.171/32", "192.0.2.0/24", "192.31.196.0/24",
            "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4",
            "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24",
            "203.0.113.0/24", "240.0.0.0/4"
        )

    NOT (
            (
                All_Traffic.app IN (
                    "*\\cscript.exe",
                    "*\\wscript.exe"
                )
                All_Traffic.dest_port IN ("80", "443", "3128")
            )
            OR
            (
                All_Traffic.app="*\\ftp.exe"
                All_Traffic.dest_port IN ("20", "21", "989", "990")
            )
            OR
            (
                All_Traffic.app IN (
                    "*\\bitsadmin.exe",
                    "*\\certutil.exe",
                    "*\\cmstp.exe",
                    "*\\hh.exe",
                    "*\\ieexec.exe",
                    "*\\msbuild.exe",
                    "*\\msdt.exe",
                    "*\\mshta.exe",
                    "*\\msiexec.exe",
                    "*\\presentationhost.exe",
                    "*\\settingsynchost.exe",
                    "*\\syncappvpublishingserver.exe",
                    "*\\workfolders.exe",
                    "*\\wuauclt.exe"
                )
                All_Traffic.dest_port IN ("80", "443")
            )
            OR
            (
                All_Traffic.app IN (
                    "*\\certutil.exe",
                    "*\\ie4uinit.exe"
                )
                All_Traffic.dest_port IN ("389")
            )
        )

    by All_Traffic.action All_Traffic.app All_Traffic.dest
       All_Traffic.dest_ip All_Traffic.dest_port
       All_Traffic.direction All_Traffic.dvc All_Traffic.protocol
       All_Traffic.protocol_version All_Traffic.src
       All_Traffic.src_ip All_Traffic.src_port
       All_Traffic.transport All_Traffic.user
       All_Traffic.vendor_product

    | `drop_dm_object_name(All_Traffic)`
    | `security_content_ctime(firstTime)`
    | `security_content_ctime(lastTime)`
    | `lolbas_network_connection_on_uncommon_port_filter`
how_to_implement: |-
    To successfully implement this detection you must ingest events into the Network Traffic data model that contain the source, destination, destination port, and communicating process name in the app field.
    Sysmon EventID 3 is a common source for this data when normalized into the Network Traffic data model.
known_false_positives: |-
    Legitimate software installation, support tooling, scripting, synchronization, or update workflows may still use uncommon ports in some environments.
    Tune approved destinations, ports, and process paths with the analytic filter macro.
references:
    - https://lolbas-project.github.io/#
    - https://www.sans.org/presentations/lolbin-detection-methods-seven-common-attacks-revealed/
drilldown_searches:
    - name: View the detection results for - "$src$"
      search: '%original_detection_search% | search  src = "$src$"'
      earliest_offset: $info_min_time$
      latest_offset: $info_max_time$
    - name: View risk events for the last 7 days for - "$src$"
      search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
      earliest_offset: 7d
      latest_offset: "0"
intermediate_findings:
    entities:
        - field: dest
          type: system
          score: 20
          message: LOLBAS process [$app$] on [$src$] connected to public destination [$dest_ip$] over uncommon port [$dest_port$].
threat_objects:
    - field: app
      type: process_name
    - field: dest_ip
      type: ip_address
analytic_story:
    - Fake CAPTCHA Campaigns
    - Living Off The Land
    - Malicious Inno Setup Loader
    - Water Gamayun
    - APT37 Rustonotto and FadeStealer
    - GhostRedirector IIS Module and Rungan Backdoor
    - Hellcat Ransomware
    - NetSupport RMM Tool Abuse
asset_type: Endpoint
mitre_attack_id:
    - T1105
    - T1567
    - T1218
product:
    - Splunk Enterprise
    - Splunk Enterprise Security
    - Splunk Cloud
category: endpoint
security_domain: network
tests:
    - name: Common Port Suppression Test
      attack_data:
        - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/lolbas_with_network_traffic/lolbas_with_network_traffic.log
          source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
          sourcetype: XmlWinEventLog
      expected_results: 1
      test_type: unit

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.