Cross-source coverage
T1065 / ATT&CK
Uncommonly Used Port
ATT&CK has retired this technique. Rules still tag it; the current id is T1571 Non-Standard Port.
2 rules across 1 source.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may conduct C2 communications over a non-standard port to bypass proxies and firewalls that have been improperly configured.
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
- —
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| fake_zoom_installerexe_devil_shadow_botnet | Undefined | YARA-L |
| turla_scheduled_task_and_host_fingerprinting_detector_sysmon_behavior | Undefined | YARA-L |