External IP address in Command Line

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query looks for command lines that contain a public IP address. Attackers may use a hard coded IP for C2 or exfiltration. This query can be filtered to exclude network prefixes that are known to be legitimate.

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 2f6032ac-bb18-48b0-855a-7b05cf074957
Tactics CommandAndControl, Exfiltration
Techniques T1041, T1071
Required Connectors SecurityEvents
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SecurityEvent/ExternalIPaddressinCommandLine.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries