Skip to content
Threat Feed

Tag

Network Connection

5 briefs RSS
high advisory

Network Communication With Crypto Mining Pools

Crypto mining malware, often deployed by various threat actors, connects to designated mining pools to perform unauthorized cryptocurrency mining, leading to significant system performance degradation and illicit resource consumption.

cryptojacking resource-hijacking malware network-connection windows
1r 1t 315i
high advisory

Detection of Unauthorized Connections to Dead Drop Resolver Domains

This brief details the detection of malicious executables establishing network connections to legitimate popular websites, known as dead drop resolvers, to conduct covert command and control (C2) communications, allowing threat actors to evade traditional security controls and maintain persistent access for data exfiltration or further compromise.

command-and-control network-connection dead-drop-resolver windows
1r 1t
medium advisory

GenAI Process Connection to Unusual Domain on macOS

This rule detects GenAI tools on macOS connecting to unusual domains, potentially indicating command and control activity, data exfiltration, or malicious payload retrieval following compromise via prompt injection, malicious MCP servers, or poisoned plugins.

Copilot +22 genai command and control macos network connection
2r 1t
medium advisory

Command Prompt Network Connection Activity

Detection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.

Microsoft Windows command-prompt network-connection execution
2r 2t
low advisory

Suspicious Command Prompt Network Connection

This alert identifies suspicious network connections initiated by the command prompt (cmd.exe) when executed with arguments indicative of script execution, remote resource access, or originating from Microsoft Office applications, which is a common tactic for downloading payloads or establishing command and control.

Elastic Defend +7 command-prompt network-connection windows execution command-and-control
2r 4t