Cross-source coverage

T1065 / ATT&CK

Uncommonly Used Port

ATT&CK has retired this technique. Rules still tag it; the current id is T1571 Non-Standard Port.

2 rules across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may conduct C2 communications over a non-standard port to bypass proxies and firewalls that have been improperly configured.

Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

2 rules
Detection Severity Format
fake_zoom_installerexe_devil_shadow_botnet Undefined YARA-L
turla_scheduled_task_and_host_fingerprinting_detector_sysmon_behavior Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.