Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1571
MITRE ATT&CK Technique

T1571: Non-Standard Port

ShareXLinkedInRedditHN

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data. Adversaries may also make changes to victim systems to abuse non-standard ports. For example, Registry keys and other configuration settings can be used to modify protocol and port pairings.(Citation: change_rdp_port_conti)

Tactics
Command and Control
Platforms
ESXi, Linux, macOS, Windows

▪Mitigations (2)

M1030Network Segmentation

Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise. Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like firewalls, routers, and cloud-based configurations. This mitigation can be implemented through the following measures: Segment Critical Systems: - Identify and group systems based on their function, sensitivity, and risk. Examples include payment systems, HR databases, production systems, and internet-facing servers. - Use VLANs, firewalls, or routers to enforce logical separation. Implement DMZ for Public-Facing Services: - Host web servers, DNS servers, and email servers in a DMZ to limit their access to internal systems. - Apply strict firewall rules to filter traffic between the DMZ and internal networks. Use Cloud-Based Segmentation: - In cloud environments, use VPCs, subnets, and security groups to isolate applications and enforce traffic rules. - Apply AWS Transit Gateway or Azure VNet peering for controlled connectivity between cloud segments. Apply Microsegmentation for Workloads: - Use software-defined networking (SDN) tools to implement workload-level segmentation and prevent lateral movement. Restrict Traffic with ACLs and Firewalls: - Apply Access Control Lists (ACLs) to network devices to enforce "deny by default" policies. - Use firewalls to restrict both north-south (external-internal) and east-west (internal-internal) traffic. Monitor and Audit Segmented Networks: - Regularly review firewall rules, ACLs, and segmentation policies. - Monitor network flows for anomalies to ensure segmentation is effective. Test Segmentation Effectiveness: - Perform periodic penetration tests to verify that unauthorized access is blocked between network segments.

M1031Network Intrusion Prevention

Use intrusion detection signatures to block traffic at network boundaries.

▪Used by groups (17)

G0032Lazarus GroupG0034Sandworm TeamG0046FIN7G0047Gamaredon GroupG0050APT32G0059Magic HoundG0064APT33G0069MuddyWaterG0090WIRTEG0091SilenceG0099APT-C-36G0105DarkVishnyaG0106RockeG1003Ember BearG1042RedEchoG1047Velvet AntG1052Contagious Interview

▪Software using this technique (41)

S0013PlugXmalwareS0021DerusbimalwareS0148RTMmalwareS0149MoonWindmalwareS0153RedLeavesmalwareS0237GravityRATmalwareS0239BankshotmalwareS0245BADCALLmalwareS0246HARDRAINmalwareS0262QuasarRATtoolS0263TYPEFRAMEmalwareS0266TrickBotmalwareS0352OSX_OCEANLOTUS.DmalwareS0367EmotetmalwareS0376HOPLIGHTmalwareS0385njRATmalwareS0412ZxShellmalwareS0428PoetRATmalwareS0455MetamorfomalwareS0491StrongPitymalwareS0493GoldenSpymalwareS0515WellMailmalwareS0574BendyBearmalwareS0687Cyclops BlinkmalwareS1016MacMamalwareS1031PingPullmalwareS1049SUGARUSHmalwareS1078RotaJakiromalwareS1085SardonicmalwareS1130Raspberry RobinmalwareS1145PikabotmalwareS1155CovenanttoolS1211HannotogmalwareS1217VIRTUALPITAmalwareS1218VIRTUALPIEmalwareS1245InvisibleFerretmalwareS1246BeaverTailmalwareS9001SystemBCmalwareS9010GlassWormmalwareS9023HiddenFacemalwareS9024SPAWNCHIMERAmalware

▪Reference

T1571on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.