This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Outbound SMTP Connections
Original Source:
[Sigma source]
Title:
Suspicious Outbound SMTP Connections
Status:
test
Description:
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1048.003/T1048.003.md#atomic-test-5---exfiltration-over-alternative-protocol---smtp
-https://www.ietf.org/rfc/rfc2821.txt
Author:
frack113
Date:
2022-01-07
modified:
2022-09-21
Tags:
-'attack.exfiltration'
-'attack.t1048.003'
Logsource:
category: network_connection
product: windows
Detection:
selection:
DestinationPort
:
-'25'
-'587'
-'465'
-'2525'
Initiated
:
'true'
filter_clients:
Image|endswith
:
-'\thunderbird.exe'
-'\outlook.exe'
filter_mailserver:
Image|startswith
:
'C:\Program Files\Microsoft\Exchange Server\'
filter_outlook:
Image|startswith
:
'C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_'
Image|endswith
:
'\HxTsr.exe'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Other SMTP tools
Level:
medium