Cross-source coverage
T1043 / ATT&CK
Commonly Used Port
ATT&CK has deprecated this technique with no replacement. Rules still tag it.
2 rules across 1 source.
8 deprecated hidden · include
From MITRE ATT&CK 19.2
This technique has been deprecated. Please use Non-Standard Port where appropriate.
Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend with normal network activity to avoid more detailed inspection. They may use commonly open ports such as
- TCP:80 (HTTP)
- TCP:443 (HTTPS)
- TCP:25 (SMTP)
- TCP/UDP:53 (DNS)
They may use the protocol associated with the port or a completely different protocol.
For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), examples of common ports are
- TCP/UDP:135 (RPC)
- TCP/UDP:22 (SSH)
- TCP/UDP:3389 (RDP)
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
- —
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 3: Network connection by · Commonly Used Port (T1043) | Low | Wazuh XML |
| Sysmon - Event 3: Network connection by · system.eventID = 3 | Low | Wazuh XML |