Office Application Initiated Network Connection Over Uncommon Ports
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "sa_network_connection" AND (IS_INITIATED = "true" AND PROCESSNAME endswith "\excel.exe,\outlook.exe,\powerpnt.exe,\winword.exe,\wordview.exe") AND (DEST_PORT != "53,80,139,443,445" AND (PROCESSNAME notcontains ":\Program Files\Microsoft Office" OR PROCESSNAME notendswith "\OUTLOOK.EXE" OR DEST_PORT != "143,465,587,993,995")) select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.PROCESSNAME,Action1.DESTINATIONHOST,Action1.DESTINATION_IPV6,Action1.DEST_IP,Action1.SOURCEHOST,Action1.SOURCE_IP,Action1.SOURCE_IPV6
Detection
Execution Mode
realtime
Log Sources
Windows
Author
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)


