Script Connecting to Rare External Host

The
Script Connecting to Rare External Host
Analytics alert indicates a Windows Script Host (wscript.exe, cscript.exe, powershell.exe) connecting to an external host.

Synopsis

10 min
3 days
14 days
10minutes
Cortex XDR agent endpoint data
Severity
Medium

Description

Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity.

Recommended For You