Umbra Wiki technique technique/T1571
Back to wiki

T1571 — Non-Standard Port

provenance: imported · ATT&CK: T1571

T1571: Non-Standard Port

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.3

Description

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.(Citation: change_rdp_port_conti)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1571
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/