Cross-source coverage
T1071.001 / ATT&CK
Application Layer Protocol: Web Protocols
100 rules across 8 sources.
4 deprecated hidden · include 15 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
NSM:FlowWinEventLog:Sysmonauditd:SYSCALLmacos:osquerymacos:unifiedlogesxi:shell
How MITRE says to detect it DET0027
Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
Windows Analytic 0075
Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.
NSM:Flowhttp.log, ssl.logWinEventLog:SysmonEventCode=3, 22
Linux Analytic 0076
Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.
NSM:Flowhttp.log, conn.logauditd:SYSCALLexecve
macOS Analytic 0077
Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields).
macos:osquerysocket_eventsmacos:unifiedloglog stream --predicate
ESXi Analytic 0078
Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.
NSM:FlowSPAN or port-mirrored HTTP/Sesxi:shell/root/.ash_history or /etc/init.d/*
Network Devices Analytic 0079
Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.
NSM:Flowhttp.log, ssl.log, websocket.log
SigmaHQ/sigma
30 rules| Detection | Severity | Format |
|---|---|---|
| APT40 Dropbox Tool User Agent | High | Sigma |
| APT User Agent | High | Sigma |
| Bitsadmin to Uncommon IP Server Address | High | Sigma |
| Bitsadmin to Uncommon TLD | High | Sigma |
| Crypto Miner User Agent | High | Sigma |
| Exploit Framework User Agent | High | Sigma |
| HackTool - CobaltStrike Malleable Profile Patterns - Proxy | High | Sigma |
| HackTool - Empire UserAgent URI Combo | High | Sigma |
| Kalambur Backdoor Curl TOR SOCKS Proxy Execution | High | Sigma |
| Katz Stealer Suspicious User-Agent | High | Sigma |
+ 20 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
28 rules| Detection | Severity | Format |
|---|---|---|
| Cobalt Strike Command and Control Beacon | High | Elastic TOML |
| Default Cobalt Strike Team Server Certificate | High | Elastic TOML |
| Halfbaked Command and Control Beacon | High | Elastic TOML |
| Outlook Home Page Registry Modification | High | Elastic TOML |
| Possible FIN7 DGA Command and Control Behavior | High | Elastic TOML |
| Suspicious Curl from macOS Application | High | Elastic TOML |
| Suspicious Curl to Google App Script Endpoint | High | Elastic TOML |
| Suspicious Execution from a WebDav Share | High | Elastic TOML |
| Curl or Wget Spawned via Node.js | Medium | Elastic TOML |
| Execution via OpenClaw Agent | Medium | Elastic TOML |
+ 18 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
15 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | Undefined | SPL |
| Cisco Secure Firewall - Connection to File Sharing Domain | Undefined | SPL |
| Cisco Secure Firewall - High EVE Threat Confidence | Undefined | SPL |
| Cisco Secure Firewall - Wget or Curl Download | Undefined | SPL |
| HTTP C2 Framework User Agent | Undefined | SPL |
| HTTP Duplicated Header | Undefined | SPL |
| HTTP Malware User Agent | Undefined | SPL |
| HTTP Possible Request Smuggling | Undefined | SPL |
| HTTP PUA User Agent | Undefined | SPL |
| HTTP Rapid POST with Mixed Status Codes | Undefined | SPL |
+ 5 more from splunk/security_content → showing the 10 highest-severity
elastic/protections-artifacts
14 rules| Detection | Severity | Format |
|---|---|---|
| Command Interpreter with IP Address Argument | Undefined | Elastic TOML |
| Curl to Telegram API | Undefined | Elastic TOML |
| Egress Network Connection Followed by Command Execution | Undefined | Elastic TOML |
| Egress Network Connection from Node.js Descendant | Undefined | Elastic TOML |
| File Download from Suspicious Top Level Domain | Undefined | Elastic TOML |
| Hidden Process Execution followed by Network Connection | Undefined | Elastic TOML |
| Python Network Connection Followed by Command Execution | Undefined | Elastic TOML |
| Suspicious Hidden Executable and Immediate Network Connection | Undefined | Elastic TOML |
| Suspicious Network Connection via Installer Package | Undefined | Elastic TOML |
| Suspicious Terraform Provider Execution and Network Connection | Undefined | Elastic TOML |
+ 4 more from elastic/protections-artifacts → showing the 10 highest-severity
socfortress/Wazuh-Rules
6 rulesAzure/Azure-Sentinel
4 rules| Detection | Severity | Format |
|---|---|---|
| RunningRAT request parameters | High | KQL |
| IP address of Windows host encoded in web request | Medium | KQL |
| Windows host username encoded in base64 web request | Medium | KQL |
| FireEye stolen red teaming tools communications | Undefined | KQL |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Potential Beaconing Activity | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| PHP web attack. | Medium | Wazuh XML |