Cross-source coverage

T1043 / ATT&CK

Commonly Used Port

ATT&CK has deprecated this technique with no replacement. Rules still tag it.

10 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

This technique has been deprecated. Please use Non-Standard Port where appropriate.

Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend with normal network activity to avoid more detailed inspection. They may use commonly open ports such as

  • TCP:80 (HTTP)
  • TCP:443 (HTTPS)
  • TCP:25 (SMTP)
  • TCP/UDP:53 (DNS)

They may use the protocol associated with the port or a completely different protocol.

For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), examples of common ports are

  • TCP/UDP:135 (RPC)
  • TCP/UDP:22 (SSH)
  • TCP/UDP:3389 (RDP)
Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

8 rules
Detection Severity Format
apt28_zekapabzebrocycannon_implant_sysmonfirewallproxy_part2 Undefined YARA-L
godlua_malware_detector_sysmon_behavior Undefined YARA-L
lojack_doubleagent_communication Undefined YARA-L
possible_cc_traffic_from_malware_variants Undefined YARA-L
rdp_login_from_localhost Undefined YARA-L
sofacy__apt_c2_domain_communication Undefined YARA-L
suspicious_typical_malware_back_connect_ports Undefined YARA-L
yispecter_malware_detection Undefined YARA-L

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Sysmon - Event 3: Network connection by · Commonly Used Port (T1043) Low Wazuh XML
Sysmon - Event 3: Network connection by · system.eventID = 3 Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.