Suspicious Outbound SMTP Connections (via network_connection)
This rule detects threat actors may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
SigmamediumWindowsv1
sigma
suspicious-outbound-smtp-connections-via-network-connection
title: Suspicious Outbound SMTP Connections (via network_connection)
id: 95b06934-f377-5e6c-b48a-53dc92cac132
status: stable
description: This rule detects threat actors may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
references:
- https://attack.mitre.org/techniques/T1048/003/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1048.003/T1048.003.md#atomic-test-5---exfiltration-over-alternative-protocol---smtp
- https://www.ietf.org/rfc/rfc2821.txt
author: Huntrule Team
date: 2026-06-16
tags:
- attack.exfiltration
- attack.t1048.003
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationPort:
- 25
- 587
- 465
- 2525
Initiated: 'true'
filter_clients:
Image|endswith:
- \thunderbird.exe
- \outlook.exe
filter_mailserver:
Image|startswith: 'C:\Program Files\Microsoft\Exchange Server\'
filter_outlook:
Image|startswith: 'C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_'
Image|endswith: '\HxTsr.exe'
filter_hr:
Image|contains: \Microsoft SQL Server\
Image|endswith: \DatabaseMail.exe
condition: (selection and not 1 of filter_*) and not filter_hr
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.