Detection of Non-Standard Port

Technique Detected:  Non-Standard Port | T1509

ID: DET0706
Domains: Mobile
Analytics: AN1827, AN1828
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1827

Many properly configured firewalls may also naturally block command and control traffic over non-standard ports.
Application vetting reports may show network communications performed by the application, including hosts, ports, protocols, and URLs. Further detection would most likely be at the enterprise level, through packet and/or netflow inspection.

Log Sources
Data Component Name Channel
Network Traffic Flow (DC0078) Network Traffic None
Network Communication (DC0113) Application Vetting None

AN1828

Many properly configured firewalls may also naturally block command and control traffic over non-standard ports.
Application vetting reports may show network communications performed by the application, including hosts, ports, protocols, and URLs. Further detection would most likely be at the enterprise level, through packet and/or netflow inspection.

Log Sources
Data Component Name Channel
Network Traffic Flow (DC0078) Network Traffic None
Network Communication (DC0113) Application Vetting None