Cross-source coverage
T1043 / ATT&CK
Commonly Used Port
ATT&CK has deprecated this technique with no replacement. Rules still tag it.
10 rules across 2 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
This technique has been deprecated. Please use Non-Standard Port where appropriate.
Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend with normal network activity to avoid more detailed inspection. They may use commonly open ports such as
- TCP:80 (HTTP)
- TCP:443 (HTTPS)
- TCP:25 (SMTP)
- TCP/UDP:53 (DNS)
They may use the protocol associated with the port or a completely different protocol.
For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), examples of common ports are
- TCP/UDP:135 (RPC)
- TCP/UDP:22 (SSH)
- TCP/UDP:3389 (RDP)
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
- —
chronicle/detection-rules
8 rules| Detection | Severity | Format |
|---|---|---|
| apt28_zekapabzebrocycannon_implant_sysmonfirewallproxy_part2 | Undefined | YARA-L |
| godlua_malware_detector_sysmon_behavior | Undefined | YARA-L |
| lojack_doubleagent_communication | Undefined | YARA-L |
| possible_cc_traffic_from_malware_variants | Undefined | YARA-L |
| rdp_login_from_localhost | Undefined | YARA-L |
| sofacy__apt_c2_domain_communication | Undefined | YARA-L |
| suspicious_typical_malware_back_connect_ports | Undefined | YARA-L |
| yispecter_malware_detection | Undefined | YARA-L |
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 3: Network connection by · Commonly Used Port (T1043) | Low | Wazuh XML |
| Sysmon - Event 3: Network connection by · system.eventID = 3 | Low | Wazuh XML |