SuspiciousExtService - description
- Last Updated: July 28, 2026
- 1 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
SuspiciousExtService detects communication with SMB, LDAP, or TACACS+ servers located outside the local network. These services are typically hosted within the local network, and outbound traffic to external servers using these protocols may indicate a device misconfiguration or a security incident.
This behavior pattern is motivated by CVE-2023-23397, a critical vulnerability in Microsoft Outlook. A crafted email sent to a victim causes the Outlook client to automatically connect to an attacker-controlled external SMB server and disclose the victim's NT LAN Manager (NTLM) hash.
Flowmon ADS detects outbound connections to external SMB, LDAP, and TACACS+ servers.
Source: Guidance for investigating attacks using CVE-2023-23397