Powered by Zoomin Software. For more details please contactZoomin

Flowmon ADS BPATTERNS Description

SuspiciousExtService - description

  • Last Updated: July 28, 2026
  • 1 minute read
    • Flowmon Products
    • Flowmon Anomaly Detection System
    • Documentation

SuspiciousExtService detects communication with SMB, LDAP, or TACACS+ servers located outside the local network. These services are typically hosted within the local network, and outbound traffic to external servers using these protocols may indicate a device misconfiguration or a security incident.

This behavior pattern is motivated by CVE-2023-23397, a critical vulnerability in Microsoft Outlook. A crafted email sent to a victim causes the Outlook client to automatically connect to an attacker-controlled external SMB server and disclose the victim's NT LAN Manager (NTLM) hash.

Flowmon ADS detects outbound connections to external SMB, LDAP, and TACACS+ servers.

Source: Guidance for investigating attacks using CVE-2023-23397

Alert