Name:LOLBAS Network Connection On Uncommon Port id:a6628e6d-be28-4278-b17d-6b5a32968eea version:1 date:None author:Steven Dick, Nasreddine Bencherchali, Splunk status:production type:Anomaly Description:The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports.
It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.
This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trusted Windows binaries.
Join this detection with the Process Execution events to provide context and avoid false positives.
Data_source:
-Sysmon EventID 3
search:| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime
how_to_implement:To successfully implement this detection you must ingest events into the Network Traffic data model that contain the source, destination, destination port, and communicating process name in the app field.
Sysmon EventID 3 is a common source for this data when normalized into the Network Traffic data model. known_false_positives:Legitimate software installation, support tooling, scripting, synchronization, or update workflows may still use uncommon ports in some environments.
Tune approved destinations, ports, and process paths with the analytic filter macro. References: -https://lolbas-project.github.io/# -https://www.sans.org/presentations/lolbin-detection-methods-seven-common-attacks-revealed/ drilldown_searches: name:'View the detection results for - "$src$"' search:'%original_detection_search% | search src = "$src$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$src$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Fake CAPTCHA Campaigns', 'Living Off The Land', 'Malicious Inno Setup Loader', 'Water Gamayun', 'APT37 Rustonotto and FadeStealer', 'GhostRedirector IIS Module and Rungan Backdoor', 'Hellcat Ransomware', 'NetSupport RMM Tool Abuse']