Windows Suspicious Outbound SMTP Connections on Common Mail Ports

Alerts on outbound, initiated SMTP connections to ports 25/465/587/2525, excluding specific mail/Exchange processes.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-07
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule flags outbound TCP connections initiated to common SMTP submission and relay ports (25, 465, 587, 2525) on Windows. Attackers may use SMTP to exfiltrate data over an unencrypted channel or to send data to an alternate external location instead of the primary command-and-control path. It relies on network connection telemetry with destination port and connection initiation indicators, and suppresses matches from specific mail clients and Microsoft Exchange app paths referenced by the rule.

Related detections9 linkedT1048.003 — drag to rearrange
FTP Data Exfiltration via curl with Embedded Credentials
Suspicious Data Exfiltration via TFTP Client
Suspicious Finger Client Execution for Command and Control
Malicious dnscat2 DNS Tunneling C2 Traffic
Suspicious Data Transfer via curl to Raw IP Address
Linux Python CLI Web Server Execution via http.server or SimpleHTTPServer
Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
PowerShell Script Exfiltration Attempt: Send-MailMessage with Attachments
Linux wget POST-file Usage Indicating Data Exfiltration
Windows Suspicious Outbound SMTP Connections on Common Mail Ports
Pivot detection · T1048.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.