{"id":"T1205.001","name":"Port Knocking","url":"https://attack.mitre.org/techniques/T1205/001","tactics":["stealth","persistence","command-and-control"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0302","stix_id":"x-mitre-detection-strategy--68b7c978-74e4-4f87-a953-2a4e752f56c2","name":"Port-knock → rule/daemon change → first successful connect (T1205.001)","url":"https://attack.mitre.org/detectionstrategies/DET0302","analytics":[{"id":"AN0842","stix_id":"x-mitre-analytic--22ff1717-6ba8-4908-b795-edf0c41a997e","name":"Analytic 0842","description":"A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port.","url":"https://attack.mitre.org/detectionstrategies/DET0302#AN0842","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall","channel":"EventCode=2004, 2005, 2006","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"wineventlog-microsoft-windows-windows-firewall-with-advanced-security-firewall"}],"mutable_elements":[{"field":"TimeWindow","description":"Seconds to correlate knock sequence → rule change → successful connect (60–300s typical)."},{"field":"MinSequenceLen","description":"Minimum number of distinct destination ports in the sequence (≥3 by default)."},{"field":"RuleChangeAllowList","description":"Accounts/processes allowed to adjust Windows Firewall (e.g., update agents)."},{"field":"WatchedPorts","description":"Ports of interest to flag when opened (e.g., 22,23,2323,8022,3389,8080)."}],"live":true,"detection_strategies":["DET0302"],"techniques":["T1205.001"]},{"id":"AN0843","stix_id":"x-mitre-analytic--7bf8954f-5028-419d-b93f-9c6bfe6e5086","name":"Analytic 0843","description":"A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source.","url":"https://attack.mitre.org/detectionstrategies/DET0302#AN0843","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Commands that alter firewall or start listeners: iptables|nft|ufw|firewall-cmd|pfctl|systemctl start sshd/telnet/dropbear; raw-socket/libpcap tools (tcpdump, tshark, nmap --raw).","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"socket/bind: New bind() to a previously closed port shortly after the sequence.","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Knock pattern: repeated REJ/S0 across ≥MinSequenceLen ports from same src_ip then SF success.","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ServicePort","description":"Candidate port expected to open after knock (e.g., 22/2323)."},{"field":"KnockTolerance","description":"Max seconds between hits inside the sequence."},{"field":"MgmtAllowList","description":"Automation allowed to change firewall/daemon state (config mgmt, orchestration)."}],"live":true,"detection_strategies":["DET0302"],"techniques":["T1205.001"]},{"id":"AN0844","stix_id":"x-mitre-analytic--39da0718-fa22-4f77-8bd2-ea8300087658","name":"Analytic 0844","description":"A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source.","url":"https://attack.mitre.org/detectionstrategies/DET0302#AN0844","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers.","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Firewall/PF anchor load or rule change events.","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Sequence of REJ/S0 then SF success from same src_ip within TimeWindow.","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PFAnchorPaths","description":"Anchors/confs to monitor (/etc/pf.conf, /etc/pf.anchors/*)."},{"field":"DevMode","description":"Suppress expected PF testing on developer devices."}],"live":true,"detection_strategies":["DET0302"],"techniques":["T1205.001"]},{"id":"AN0845","stix_id":"x-mitre-analytic--fe82e2a6-a928-4fe0-a899-fead90eabb29","name":"Analytic 0845","description":"Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success.","url":"https://attack.mitre.org/detectionstrategies/DET0302#AN0845","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"Config/ACL changes, line vty transport input changes, telnet/ssh/http(s) enable, image/feature module changes.","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"Series of denied/closed flows to distinct ports then success to mgmt port from same src_ip within TimeWindow.","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MgmtPortSet","description":"Mgmt ports to focus on: 22,23,2323,80,443,161,4786."},{"field":"DeviceRole","description":"Tighten thresholds on edge/internet-facing devices."}],"live":true,"detection_strategies":["DET0302"],"techniques":["T1205.001"]}],"live":true,"version":"1.0","techniques":["T1205.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}