ATT&CK · T1571
Non-Standard Port
Tactics: command-and-control
About
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data. Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.
Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
17 known groups
Software
41 malware/tools implement this
PlugXDerusbiRTMMoonWindRedLeavesGravityRATBankshotBADCALLHARDRAINQuasarRATTYPEFRAMETrickBotOSX_OCEANLOTUS.DEmotetHOPLIGHTnjRATZxShellPoetRATMetamorfoStrongPityGoldenSpyWellMailBendyBearCyclops BlinkMacMaPingPullSUGARUSHRotaJakiroSardonicRaspberry RobinPikabotCovenantHannotogVIRTUALPITAVIRTUALPIEInvisibleFerretBeaverTailSystemBCGlassWormHiddenFaceSPAWNCHIMERA
Corpus indicators tagged with this technique
764 indicators in the corpus carry T1571.
Showing the top 30 by severity of 764.