Home >
Enterprise >
Participants >
Symantec >
Commonly Used Port (T1043)
|
|
See technique results for:
Carbanak+FIN7 |
||
The technique was not in scope. |
APT29 |
||||||
Step | ATT&CK Pattern |
|
||||
3.B.3
|
Tactic Command and Control (TA0011) |
|
||||
11.A.13
|
Tactic Command and Control (TA0011) |
|
Procedure
Established C2 channel (192.168.0.4) via PowerShell payload over port 443
Criteria
Established network channel over port 443
Footnotes
- The telemetry was acquired by manually initiating an export of endpoint-stored event data that was not automatically sent to the analysis system, which caused this detection to receive Delayed (Manual).

