External IP address in Command Line

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query looks for command lines that contain a public IP address. Attackers may use a hard coded IP for C2 or exfiltration. This query can be filtered to exclude network prefixes that are known to be legitimate.

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 2f6032ac-bb18-48b0-855a-7b05cf074957
Tactics CommandAndControl, Exfiltration
Techniques T1041, T1071
Required Connectors SecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SecurityEvent EventID == "4688" ?

Associated Connectors

The following connectors provide data for this content item:

Connector Solution
WindowsSecurityEvents Windows Security Events

Solutions: Windows Security Events


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries