Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0302 — Port-knock → rule/daemon change → first successful connect (T1205.001)
DET0302

Port-knock → rule/daemon change → first successful connect (T1205.001)

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0842 Analytic 0842
Windows

A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall EventCode=2004, 2005, 2006
[TimeWindow] Seconds to correlate knock sequence → rule change → successful connect (60–300s typical).
[MinSequenceLen] Minimum number of distinct destination ports in the sequence (≥3 by default).
[RuleChangeAllowList] Accounts/processes allowed to adjust Windows Firewall (e.g., update agents).
[WatchedPorts] Ports of interest to flag when opened (e.g., 22,23,2323,8022,3389,8080).
AN0843 Analytic 0843
Linux

A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source.

auditd:SYSCALL execve: Commands that alter firewall or start listeners: iptables|nft|ufw|firewall-cmd|pfctl|systemctl start sshd/telnet/dropbear; raw-socket/libpcap tools (tcpdump, tshark, nmap --raw). auditd:SYSCALL socket/bind: New bind() to a previously closed port shortly after the sequence. NSM:Flow Knock pattern: repeated REJ/S0 across ≥MinSequenceLen ports from same src_ip then SF success.
[ServicePort] Candidate port expected to open after knock (e.g., 22/2323).
[KnockTolerance] Max seconds between hits inside the sequence.
[MgmtAllowList] Automation allowed to change firewall/daemon state (config mgmt, orchestration).
AN0844 Analytic 0844
macOS

A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source.

macos:unifiedlog exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers. macos:unifiedlog Firewall/PF anchor load or rule change events. NSM:Flow Sequence of REJ/S0 then SF success from same src_ip within TimeWindow.
[PFAnchorPaths] Anchors/confs to monitor (/etc/pf.conf, /etc/pf.anchors/*).
[DevMode] Suppress expected PF testing on developer devices.
AN0845 Analytic 0845
Network Devices

Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success.

networkdevice:syslog Config/ACL changes, line vty transport input changes, telnet/ssh/http(s) enable, image/feature module changes. NSM:Flow Series of denied/closed flows to distinct ports then success to mgmt port from same src_ip within TimeWindow.
[MgmtPortSet] Mgmt ports to focus on: 22,23,2323,80,443,161,4786.
[DeviceRole] Tighten thresholds on edge/internet-facing devices.

Detected Techniques

1

Details

MITRE ID
DET0302
STIX ID
x-mitre-detection-strategy--68b7c978-74e4-4f87-a953-2a4e752f56c2
Analytics
4
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.