Suspicious Outbound Network Connection from explorer.exe

PremiumReviewedSigma · Medium · v1
Product
windows
Category
network_connection
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Priv Esc → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects explorer.exe initiating an outbound network connection to an external host, anomalous behavior consistent with the DOUBLELOADER backdoor injecting into explorer.exe and beaconing to command-and-control. explorer.exe does not normally make direct external connections, so this pattern indicates process injection and covert C2.

Related detections8 linkedT1071 — drag to rearrange
Suspicious SSH Service on Non Standard Port 57722
Suspicious Remote Thread Created in notepad Process
Suspicious Bash Reverse Shell via /dev/tcp
Windows GitHub Self-Hosted Runner Execution via Runner.Worker and Runner.Listener
macOS Installer Scripts Spawning Suspicious Interpreter Child Processes
Windows DNS analytic events for GALLIUM-related ddns QNAMEs (EventID 257)
Windows Process Creation alerts on GALLIUM-associated hash IOCs
Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Suspicious Outbound Network Connection from explorer.exe
Pivot detection · T1071 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.