T1571 — Non-Standard Port
T1571: Non-Standard Port
MITRE ATT&CK® Enterprise technique
| Tactics | Command And Control |
| Platforms | ESXi, Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.3 |
Description
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.
Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.(Citation: change_rdp_port_conti)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1571
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/