Suspicious Python Initiated Connection (via network_connection)
This rule detects a Python process initiating a network connection. While this frequently relates to package installation, it can also indicate a potential hostile script communicating with a C&C server.
SigmamediumWindowsv1
sigma
suspicious-python-initiated-connection-via-network-connection
title: Suspicious Python Initiated Connection (via network_connection)
id: 8f3263b1-2d3f-5da2-a6ae-9b23559f5a36
status: stable
description: This rule detects a Python process initiating a network connection. While this frequently relates to package installation, it can also indicate a potential hostile script communicating with a C&C server.
references:
- https://attack.mitre.org/techniques/T1046/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1046/T1046.md#atomic-test-4---port-scan-using-python
- https://pypi.org/project/scapy/
author: Huntrule Team
date: 2026-07-06
tags:
- attack.discovery
- attack.t1046
logsource:
category: network_connection
product: windows
definition: 'Requirements: Field enrichment is required for the filters to work. As field such as CommandLine and ParentImage are not available by default on this event type'
detection:
selection:
Initiated: 'true'
Image|contains|all:
- '\python'
- '.exe'
filter_optional_conda:
ParentImage: C:\ProgramData\Anaconda3\Scripts\conda.exe
CommandLine|contains|all:
- ':\ProgramData\Anaconda3\Scripts\conda-script.py'
- 'update'
filter_optional_conda_jupyter_notebook:
ParentImage: C:\ProgramData\Anaconda3\python.exe
CommandLine|contains: 'C:\ProgramData\Anaconda3\Scripts\jupyter-notebook-script.py'
filter_main_local_communication:
DestinationIp: 127.0.0.1
SourceIp: 127.0.0.1
filter_main_pip:
CommandLine|contains|all:
- 'pip.exe'
- 'install'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.