Cross-source coverage

T1043 / ATT&CK

Commonly Used Port

ATT&CK has deprecated this technique with no replacement. Rules still tag it.

2 rules across 1 source.

8 deprecated hidden · include

From MITRE ATT&CK 19.2

This technique has been deprecated. Please use Non-Standard Port where appropriate.

Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend with normal network activity to avoid more detailed inspection. They may use commonly open ports such as

  • TCP:80 (HTTP)
  • TCP:443 (HTTPS)
  • TCP:25 (SMTP)
  • TCP/UDP:53 (DNS)

They may use the protocol associated with the port or a completely different protocol.

For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), examples of common ports are

  • TCP/UDP:135 (RPC)
  • TCP/UDP:22 (SSH)
  • TCP/UDP:3389 (RDP)
Platforms
Linux · macOS · Windows
Telemetry

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Sysmon - Event 3: Network connection by · Commonly Used Port (T1043) Low Wazuh XML
Sysmon - Event 3: Network connection by · system.eventID = 3 Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.