Compliance Node Overview
MITRE ATT&CK T1205.001 (Port Knocking) is an Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port, an adversary sends a series of attempted connections to a predefined sequence of closed ports. After the sequence is completed, opening a port is often accomplished by the host based firewall, but could also be implemented by custom software. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, CA-07, CM-02, CM-06, CM-07, SC-07, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1205/001/
SHA-256 integrity: 8e51f5c5428ab21b3f771d0c3d08d7c465e7b708fd8bf6db7570f30997870c1d
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1205.001: Port Knocking (https://attack.mitre.org/techniques/T1205/001/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access