Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1571

T1571Non-Standard Port

T1571 — Non-Standard Port is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 23 detection use cases covering it and 18 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
23Use cases
18Articles
0Sub-techniques
1Tactic

Use cases covering this technique (23)

Ollama Abnormal Network Connectivity ESCU actions · hunting P Cisco NVM - Outbound Connection to Suspicious Port ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - File Download Over Uncommon Port ESCU actions · hunting P [LLM] RAT C2 egress to hardcoded joyfill IPs and /$/boot request paths Bespoke c2 · hunting DSΣPDDCS [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] Egress to Dysphoria distribution-node / relay IPs (194.87.198.x, 194.58.38.x) Bespoke c2 · hunting DSΣPDDCS [LLM] HelloProxy listener: svchost.exe binding TCP 5003/5060 Bespoke c2 · alerting DSP [LLM] Outbound C2 to Miasma controller 85.137.53.71 on ports 8080/8081/8091 Bespoke c2 · hunting DSΣPDDCS [LLM] TuxBot/Akiru IoT botnet C2 connection to known infrastructure Bespoke c2 · hunting DSΣPCS [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] UAT-7810 self-signed 'exploit' TLS certificate served on non-standard port 99 Bespoke c2 · hunting DSΣPDDCS [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress to ClawHavoc cluw / AMOS C2 infrastructure Bespoke c2 · hunting DSΣPCS [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 Bespoke c2 · hunting DSΣPDDCS [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Bespoke delivery · alerting DSΣPDDCS [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection Bespoke install · alerting DSPDDCS [LLM] Interactive shell process initiating outbound network connection (reverse-shell C2) Bespoke c2 · hunting DSPCS [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) Bespoke c2 · alerting DSΣPDDCS [LLM] Exfil to jeIlyfish C2 68.183.212.246:32258 Bespoke actions · hunting DSΣPDDCS

Articles citing this technique (18)