MITRE ATT&CK Technique
T1571Non-Standard Port
- First Reported
- Sep 8, 2026
- Latest Reported
- Sep 8, 2026
Official Description
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.
Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.(Citation: change_rdp_port_conti)
Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.(Citation: change_rdp_port_conti)
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Windows
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Reported Context (1)
- The backdoor uses raw-TCP C2 on port 27015 in one build and was observed connecting on port 27017 in another. HVNC Backdoor Uses Fake Tax and DocuSign Lures to Target Latin American Organizations
Threat Actors (1)
MITRE ATT&CK (14)
Vendors (3)
Products (4)
Tools (7)
Industries (2)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.