Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0524 — Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205
DET0524

Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1448 Analytic 1448
Windows

A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall EventCode=2004, 2005, 2006 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
[TimeWindowKnock] Window to correlate knock sequence → rule change → successful connect (e.g., 120s).
[PortSequenceMinLen] Minimum number of distinct closed ports hit before success (e.g., 3).
[SuspiciousProcesses] List of binaries that commonly toggle firewall/sniff (netsh.exe, powershell.exe, npcapservice.exe, windivert, rawsock tools).
[AllowedFirewallChangers] Service accounts or software update agents allowed to change firewall.
[WoLAllowedWindows] Maintenance windows when magic packets are expected.
AN1449 Analytic 1449
Linux

Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values.

auditd:SYSCALL execve: Commands altering firewall or enabling listeners (iptables, nft, ufw, firewall-cmd, systemctl start *ssh*/*telnet*, ip route add, tcpdump, tshark) auditd:SYSCALL socket/bind: Process binds to a new local port shortly after knock NSM:Flow Knock pattern: multiple REJ/S0 to distinct closed ports then successful connection to service_port NSM:Flow Packets with unusual flags or payloads outside established flows (e.g., WoL magic FF×6 + 16×MAC)
[ServicePort] Port that becomes available post-knock (e.g., 22/8022/2323).
[KnockResetRatio] Percentage of failed attempts with RST/ICMP vs SYN/SYN-ACK to qualify as closed-port probing.
[ProcessAllowList] Automation expected to touch firewall/daemon configs (config-mgmt agents).
AN1450 Analytic 1450
macOS

Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment.

macos:unifiedlog exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers macos:unifiedlog Firewall rule enable/disable or listen socket changes NSM:Flow Closed-port hits followed by success from same src_ip
[PFAnchorPaths] Anchors or conf files monitored for change (/etc/pf.conf, /etc/pf.anchors/*).
[DeveloperMode] Reduce noise on dev endpoints compiling or testing PF rules.
AN1451 Analytic 1451
Network Devices

Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session.

networkdevice:syslog Config/ACL/line vty changes, service enable (telnet/ssh/http(s)), module reloads NSM:Flow Port-knock pattern from one src to device unicast,broadcast,network addresses on same port within TimeWindowKnock
[MgmtPortSet] Ports whose sudden enablement should alert (23, 22, 2323, 80/443, 4786).
[DeviceRole] Applies different thresholds to core/edge/branch devices.

Detected Techniques

1

Details

MITRE ID
DET0524
STIX ID
x-mitre-detection-strategy--1e601759-c5d1-45cc-97a1-972967426794
Analytics
4
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.