Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1571

T1571Non-Standard Port

T1571 — Non-Standard Port is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 24 detection use cases covering it and 17 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
24Use cases
17Articles
0Sub-techniques
1Tactic

Use cases covering this technique (24)

Ollama Abnormal Network Connectivity ESCU actions · hunting P Cisco NVM - Outbound Connection to Suspicious Port ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - File Download Over Uncommon Port ESCU actions · hunting P [LLM] PATCHCORD C2 beacon to appstoore.solutions / 46.30.188.13:8080 Bespoke c2 · hunting DSΣPDDCS [LLM] Reverse shell / Meterpreter egress from Flowise node or its shell child Bespoke c2 · hunting DSPCS [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) Bespoke c2 · alerting DSPCS [LLM] Reverse-shell egress from netcat/socat on Flowise host Bespoke c2 · alerting DSΣPCS [LLM] Custom \GET obfuscated exfiltration to 18.228.188.56 / SHA256-tracked sample Bespoke actions · hunting DSΣPDDCS [LLM] Hardcoded WebSocket backdoor to 154.92.19.71:39989 (no DNS) Bespoke c2 · hunting DSΣPDDCS [LLM] ZT-IP hunt: direct-to-IP egress with no preceding DNS resolution Bespoke c2 · hunting DSPDDCS [LLM] Miasma RAT C2 beacon to 85.137.53.71 from Node.js runtime Bespoke c2 · hunting DSΣPDDCS [LLM] TuxBot/Akiru IoT botnet C2 connection to known infrastructure Bespoke c2 · hunting DSΣPCS [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) Bespoke c2 · hunting DSΣPDDCS [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 Bespoke c2 · hunting DSΣPDDCS [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Bespoke delivery · alerting DSΣPDDCS [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection Bespoke install · alerting DSPDDCS [LLM] Interactive shell process initiating outbound network connection (reverse-shell C2) Bespoke c2 · hunting DSPCS [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) Bespoke c2 · alerting DSΣPDDCS [LLM] Exfil to jeIlyfish C2 68.183.212.246:32258 Bespoke actions · hunting DSΣPDDCS

Articles citing this technique (17)