Splunk released an anomaly detection for Windows Living Off the Land Binaries and Scripts (LOLBAS) establishing public network connections on destination ports that are unusual for the originating process. Such activity can indicate command-and-control communications, payload transfer, proxy execution, or defense evasion using legitimate Windows utilities.
The analytic queries the Splunk Network Traffic data model, excludes private and reserved destination ranges, and applies binary-specific expected-port exclusions to limit false positives. It requires normalized network telemetry—such as Sysmon Event ID 3—is disabled by default, and generates intermediate risk events rather than direct notable events, enabling SOC teams to correlate suspicious LOLBAS traffic with ATT&CK-tracked adversary behavior.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk updated its "LOLBAS Network Connection On Uncommon Port" anomaly detection for Splunk Enterprise Security. The analytic identifies Windows LOLBAS processes making public network connections over ports atypical for the process and generates intermediate risk events.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.