{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/t1571/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["command-and-control","t1571","windows","powershell"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently employ techniques to evade network monitoring by utilizing protocols and port pairings that are not traditionally associated with specific traffic types. By establishing command-and-control (C2) channels over non-standard ports, such as 8088 or 587, attackers attempt to blend in with authorized traffic and bypass static firewall rules or simple inspection policies. The PowerShell cmdlet \u003ccode\u003eTest-NetConnection\u003c/code\u003e is often misused by attackers during the post-exploitation reconnaissance phase to verify reachability and ensure that a target host can communicate with external C2 infrastructure over these unconventional ports. This brief focuses on the detection of such reconnaissance activity using PowerShell Script Block Logging, which provides visibility into the parameters passed to network diagnostic commands.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of non-standard port communication allows attackers to maintain persistent, covert C2 channels, potentially leading to unauthorized data exfiltration, lateral movement, or long-term remote administration of compromised endpoints. Detecting this activity early in the network reconnaissance phase is critical to preventing the establishment of a stable C2 infrastructure and mitigating further compromise within the target environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying suspicious usage of network connectivity tools in scripting environments.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable PowerShell Script Block Logging (Event ID 4104) across all Windows endpoints to capture the command-line arguments used in administrative tools.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided below to the SIEM and tune the filter list to exclude known administrative or monitoring tools specific to the local network environment.\u003c/li\u003e\n\u003cli\u003eMonitor logs for instances of \u003ccode\u003eTest-NetConnection\u003c/code\u003e where the destination port does not align with standardized port assignments (e.g., ports other than 80, 443).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:18:58Z","date_published":"2026-09-01T12:18:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-uncommon-port-testing/","summary":"This brief documents a detection capability for identifying potential command-and-control activity where adversaries use PowerShell to test network connectivity over non-standard, uncommon ports.","title":"Detection of Non-Standard Network Port Usage via PowerShell","url":"https://feed.craftedsignal.io/briefs/2026-09-uncommon-port-testing/"}],"language":"en","title":"CraftedSignal Threat Feed - T1571","version":"https://jsonfeed.org/version/1.1"}