• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Past Connection to a New Suspicious IP Address

Risk Factors

Attackers frequently set up websites and servers to distribute malware, communicate with command-and-control servers, or collect exploitable information from victims. The IP addresses associated with malware and known malicious servers can be identified from threat intelligence, which is a collection of information curated by the security community. Devices that communicate with suspicious IP addresses should be investigated for vulnerabilities to exploits that could expose information or result in a persistent attack on the network.

The system might change the risk score for this detection.

Kill Chain

Caution

Risk Score

60

Detection diagram
Next in Caution: Past Connection to a New Suspicious URI

Attack Background

N/A

Mitigation Options

Block inbound and outbound traffic from suspicious IP addresses at the network perimeter
Quarantine the device while checking for indicators of compromise, such as the presence of malware
Implement network segmentation and the principle of least privilege on accounts to minimize the damage caused by a compromised device

MITRE ATT&CK ID

What else can RevealX do for you?