{"id":"T1571","name":"Non-Standard Port","url":"https://attack.mitre.org/techniques/T1571","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0227","stix_id":"x-mitre-detection-strategy--cc8324a7-03d0-47d1-8e2b-3caec44fc129","name":"Detection Strategy for Non-Standard Ports","url":"https://attack.mitre.org/detectionstrategies/DET0227","analytics":[{"id":"AN0633","stix_id":"x-mitre-analytic--9ea7f21e-700f-4900-a1d4-dfc171d399fe","name":"Analytic 0633","description":"Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports.","url":"https://attack.mitre.org/detectionstrategies/DET0227#AN0633","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5156, 5157","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"PortThresholds","description":"Define what constitutes a 'non-standard port' based on organizational baselines (e.g., allow 443/80/22 but flag 8088/587/3389 changes)."},{"field":"ProcessAllowList","description":"Processes normally allowed to use non-standard ports (e.g., custom apps)."},{"field":"TimeWindow","description":"Correlate process creation and network activity within N seconds."}],"live":true,"detection_strategies":["DET0227"],"techniques":["T1571"]},{"id":"AN0634","stix_id":"x-mitre-analytic--dba32c3a-1ae7-46a4-9b04-d011f37aa801","name":"Analytic 0634","description":"Unusual daemons or user processes binding/listening on ports outside of standard ranges, or initiating client connections using mismatched protocol/port pairings.","url":"https://attack.mitre.org/detectionstrategies/DET0227#AN0634","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket/connect syscalls","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"processes binding to non-standard ports or sshd configured on unexpected port","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"process listening or connecting on non-standard ports","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"AllowedServices","description":"Exclude ports intentionally configured for enterprise apps."},{"field":"PayloadEntropyThreshold","description":"Define thresholds for anomalous payload entropy to catch tunneled traffic."}],"live":true,"detection_strategies":["DET0227"],"techniques":["T1571"]},{"id":"AN0635","stix_id":"x-mitre-analytic--785c44d0-7e5b-4d3e-a3cd-0c5e96b8891b","name":"Analytic 0635","description":"Applications making outbound connections on non-standard ports or launchd services bound to ports inconsistent with system baselines.","url":"https://attack.mitre.org/detectionstrategies/DET0227#AN0635","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"outbound TCP/UDP traffic over unexpected port","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"launchd services binding to non-standard ports","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"BaselinePortProfiles","description":"Define expected macOS service port usage (e.g., AirDrop, Bonjour)."}],"live":true,"detection_strategies":["DET0227"],"techniques":["T1571"]},{"id":"AN0636","stix_id":"x-mitre-analytic--4e3afe58-e384-4b9e-9137-adaa0bac72af","name":"Analytic 0636","description":"VM services or management daemons communicating on ports not defined by VMware defaults, such as vpxa or hostd processes initiating traffic over high-numbered or unexpected ports.","url":"https://attack.mitre.org/detectionstrategies/DET0227#AN0636","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"ESXi service connections on unexpected ports","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vpxd"},{"name":"esxcli:network","channel":"listening sockets bound to non-standard ports","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxcli-network"}],"mutable_elements":[{"field":"ESXiAllowedPorts","description":"Default VMware service ports that should not be flagged."}],"live":true,"detection_strategies":["DET0227"],"techniques":["T1571"]}],"live":true,"version":"1.0","techniques":["T1571"]}],"sigma_rules":[{"id":"4b89abaa-99fe-4232-afdd-8f9aa4d20382","title":"Potentially Suspicious Malware Callback Communication","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-03-19","modified":"2024-03-12","description":"Detects programs that connect to known malware callback ports based on statistical analysis from two different sandbox system databases\n","references":["https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.persistence","attack.command-and-control","attack.t1571"],"path":"rules/windows/network_connection/net_connection_win_susp_malware_callback_port.yml","techniques":["T1571"],"cves":[]},{"id":"6d8c3d20-a5e1-494f-8412-4571d716cf5c","title":"Communication To Uncommon Destination Ports","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-03-19","modified":"2024-03-12","description":"Detects programs that connect to uncommon destination ports","references":["https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.persistence","attack.command-and-control","attack.t1571"],"path":"rules/windows/network_connection/net_connection_win_susp_malware_callback_ports_uncommon.yml","techniques":["T1571"],"cves":[]},{"id":"adf876b3-f1f8-4aa9-a4e4-a64106feec06","title":"Testing Usage of Uncommonly Used Port","author":"frack113","status":"test","level":"medium","date":"2022-01-23","modified":null,"description":"Adversaries may communicate using a protocol and port paring that are typically not associated.\nFor example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1571/T1571.md#atomic-test-1---testing-usage-of-uncommonly-used-port-with-powershell","https://learn.microsoft.com/en-us/powershell/module/nettcpip/test-netconnection?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.command-and-control","attack.t1571"],"path":"rules/windows/powershell/powershell_script/posh_ps_test_netconnection.yml","techniques":["T1571"],"cves":[]},{"id":"dbfc7c98-04ab-4ab7-aa94-c74d22aa7376","title":"Potentially Suspicious Malware Callback Communication - Linux","author":"hasselj","status":"test","level":"high","date":"2024-05-10","modified":null,"description":"Detects programs that connect to known malware callback ports based on threat intelligence reports.\n","references":["https://www.mandiant.com/resources/blog/triton-actor-ttp-profile-custom-attack-tools-detections","https://www.mandiant.com/resources/blog/ukraine-and-sandworm-team","https://www.elastic.co/guide/en/security/current/potential-non-standard-port-ssh-connection.html","https://thehackernews.com/2024/01/systembc-malwares-c2-server-analysis.html","https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.persistence","attack.command-and-control","attack.t1571"],"path":"rules/linux/network_connection/net_connection_lnx_susp_malware_callback_port.yml","techniques":["T1571"],"cves":[]},{"id":"ede05abc-2c9e-4624-9944-9ff17fdc0bf5","title":"Suspicious DNS Z Flag Bit Set","author":"@neu5ron, SOC Prime Team, Corelight","status":"test","level":"medium","date":"2021-05-04","modified":"2022-11-29","description":"The DNS Z flag is bit within the DNS protocol header that is, per the IETF design, meant to be used reserved (unused).\nAlthough recently it has been used in DNSSec, the value being set to anything other than 0 should be rare.\nOtherwise if it is set to non 0 and DNSSec is being used, then excluding the legitimate domains is low effort and high reward.\nDetermine if multiple of these files were accessed in a short period of time to further enhance the possibility of seeing if this was a one off or the possibility of larger sensitive file gathering.\nThis Sigma query is designed to accompany the Corelight Threat Hunting Guide, which can be found here: https://www3.corelight.com/corelights-introductory-guide-to-threat-hunting-with-zeek-bro-logs'\n","references":["https://twitter.com/neu5ron/status/1346245602502443009","https://tdm.socprime.com/tdm/info/eLbyj4JjI15v#sigma","https://tools.ietf.org/html/rfc2929#section-2.1","https://www.netresec.com/?page=Blog&month=2021-01&post=Finding-Targeted-SUNBURST-Victims-with-pDNS"],"logsource":{"product":"zeek","service":"dns"},"tags":["attack.t1095","attack.t1571","attack.command-and-control"],"path":"rules/network/zeek/zeek_dns_susp_zbit_flag.yml","techniques":["T1095","T1571"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-38035","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}