Non-Standard Port T1571

Tactic: Command & Control

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Events covered

11 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 26 rules share fields, values, and exclusions.

Fields filtered most (56 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
DestinationPort10eq 4, is_not_null 2, lt 2, cross_field_compare 1, in 1, ne 12200, 2222, 4000, 49152, 100
src_ip7cidr_match 2, cross_field_compare 2, is_not_null 2, in 110.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16
dest_ip6cidr_match 3, is_not_null 2, eq 110.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, malicious_ips
EventType5eq 4, in 1exec, connection_attempted, connectionevent, disconnect_received, fileevent
TimeDeltainSeconds4gt 425, 10, 60
sourcetype4eq 3, in 1cisco:sfw:estreamer, cisco:nvm:flowdata, cisco:nvm:flowdata:v2, ollama:server
BeaconPercent3gt 380
Initiated3eq 3true
TotalEvents3gt 330, 15
DestinationHostname2is_null 2
DeviceVendor2eq 2Fortinet, Palo Alto Networks
Image2starts_with 2c:\program files (x86)\, c:\program files\
LearningTimeProtocol2cross_field_compare 2, is_not_null 1AlertTimeProtocol
MostFrequentTimeDeltaCount2gt 225
SourceIP2cross_field_compare 2, is_not_null 1, ne 1nextSourceIP, 0.0.0.0

Top indicator values (209 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
BeaconPercentgt
80
33
Initiatedeq
true
350
dest_ipcidr_match
10.0.0.0/8
39
dest_ipcidr_match
127.0.0.0/8
310
dest_ipcidr_match
169.254.0.0/16
39
dest_ipcidr_match
172.16.0.0/12
39
dest_ipcidr_match
192.168.0.0/16
39
dest_ipcidr_match
::1/128
33
dest_ipcidr_match
fc00::/7
32
dest_ipcidr_match
fe80::/10
32
DestinationPorteq
4444
22
DestinationPortlt
49152
22
EventTypeeq
exec
2576
Imagestarts_with
c:\program files (x86)\
2
Imagestarts_with
c:\program files\
2
LearningTimeProtocolcross_field_compare
AlertTimeProtocol
22
MostFrequentTimeDeltaCountgt
25
22
SourceIPcross_field_compare
nextSourceIP
22
TimeDeltainSecondsgt
25
22
TotalEventsgt
30
22
event.typeeq
start
21078
sourcetypeeq
cisco:sfw:estreamer
232
src_ipcidr_match
10.0.0.0/8
29
src_ipcidr_match
127.0.0.0/8
212
src_ipcidr_match
169.254.0.0/16
28
src_ipcidr_match
172.16.0.0/12
29
src_ipcidr_match
192.168.0.0/16
29
Actioneq
Denied
1
Activityeq
TRAFFIC
1
AlertTimeSrcIpDenyRateCountcross_field_compare
LearningThreshold
12

Exclusions (128 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
8
dest_ipcidr_match
127.0.0.0/8
8
dest_ipcidr_match
169.254.0.0/16
8
dest_ipcidr_match
172.16.0.0/12
8
dest_ipcidr_match
192.168.0.0/16
8
dest_ipcidr_match
::1/128
3
dest_ipcidr_match
fc00::/7
3
dest_ipcidr_match
fe80::/10
3
DestinationPortin
443
3
DestinationPortin
80
3
DestinationIPcidr_match
10.0.0.0/8
2
DestinationIPcidr_match
127.0.0.0/8
2
DestinationIPcidr_match
169.254.0.0/16
2
DestinationIPcidr_match
172.16.0.0/12
2
DestinationIPcidr_match
192.168.0.0/16
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 5 rules

Elastic 6 rules

Splunk 4 rules

Kusto 9 rules

Panther 2 rules