• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

TLS Connection to a Suspicious Domain

Risk Factors

Attackers frequently establish websites that are designed to distribute malware or collect information from victims. The domains of known malicious websites can be included in threat intelligence, which is a collection of information curated by the security community. Network clients that communicate with a suspicious domain should be investigated. These clients might be vulnerable to machine-in-the-middle, phishing, or pharming attacks, which could result in the exposure of information.

Kill Chain

Caution

Risk Score

60

Detection diagram
Next in Caution: Treck TCP/IP Network Stack Detected

Attack Background

N/A

Mitigation Options

Block inbound and outbound traffic from suspicious domains at the network perimeter
Quarantine the device while checking for indicators of compromise, such as the presence of malware
Implement network segmentation, security zones, and firewall policies that limit how devices can communicate

MITRE ATT&CK ID

What else can RevealX do for you?