Detection rules › Sigma

Network Communication Initiated To Portmap.IO Domain

Severity
medium
Author
Florian Roth (Nextron Systems)
Source
upstream

Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors

MITRE ATT&CK coverage

TacticTechniques
Command & ControlT1090.002 Proxy: External Proxy
ExfiltrationT1041 Exfiltration Over C2 Channel

Event coverage

ProviderEvent IDTitle
Sysmon3Network connection

Stages and Predicates

Stage 1: selection

DestinationHostname|endswith: .portmap.io
Initiated: true

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
DestinationHostnameends_with
  • .portmap.io
Initiatedeq
  • true corpus 40 (sigma 40)