Cross-source coverage

T1071.001 / ATT&CK

Application Layer Protocol: Web Protocols

104 rules across 9 sources.

15 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
NSM:FlowWinEventLog:Sysmonauditd:SYSCALLmacos:osquerymacos:unifiedlogesxi:shell

How MITRE says to detect it DET0027

Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Windows Analytic 0075

Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.

  • NSM:Flow http.log, ssl.log
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0076

Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.

  • NSM:Flow http.log, conn.log
  • auditd:SYSCALL execve

macOS Analytic 0077

Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields).

  • macos:osquery socket_events
  • macos:unifiedlog log stream --predicate

ESXi Analytic 0078

Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.

  • NSM:Flow SPAN or port-mirrored HTTP/S
  • esxi:shell /root/.ash_history or /etc/init.d/*

Network Devices Analytic 0079

Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.

  • NSM:Flow http.log, ssl.log, websocket.log

SigmaHQ/sigma

30 rules
Detection Severity Format
APT40 Dropbox Tool User Agent High Sigma
APT User Agent High Sigma
Bitsadmin to Uncommon IP Server Address High Sigma
Bitsadmin to Uncommon TLD High Sigma
Crypto Miner User Agent High Sigma
Exploit Framework User Agent High Sigma
HackTool - CobaltStrike Malleable Profile Patterns - Proxy High Sigma
HackTool - Empire UserAgent URI Combo High Sigma
Kalambur Backdoor Curl TOR SOCKS Proxy Execution High Sigma
Katz Stealer Suspicious User-Agent High Sigma

+ 20 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

30 rules
Detection Severity Format
Cobalt Strike Command and Control Beacon High Elastic TOML
Default Cobalt Strike Team Server Certificate High Elastic TOML
Deprecated - SUNBURST Command and Control Activity High Elastic TOML
Halfbaked Command and Control Beacon High Elastic TOML
Outlook Home Page Registry Modification High Elastic TOML
Possible FIN7 DGA Command and Control Behavior High Elastic TOML
Suspicious Curl from macOS Application High Elastic TOML
Suspicious Curl to Google App Script Endpoint High Elastic TOML
Suspicious Execution from a WebDav Share High Elastic TOML
Curl or Wget Spawned via Node.js Medium Elastic TOML

+ 20 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

15 rules
Detection Severity Format
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Undefined SPL
Cisco Secure Firewall - Connection to File Sharing Domain Undefined SPL
Cisco Secure Firewall - High EVE Threat Confidence Undefined SPL
Cisco Secure Firewall - Wget or Curl Download Undefined SPL
HTTP C2 Framework User Agent Undefined SPL
HTTP Duplicated Header Undefined SPL
HTTP Malware User Agent Undefined SPL
HTTP Possible Request Smuggling Undefined SPL
HTTP PUA User Agent Undefined SPL
HTTP Rapid POST with Mixed Status Codes Undefined SPL

+ 5 more from splunk/security_content → showing the 10 highest-severity

elastic/protections-artifacts

14 rules
Detection Severity Format
Command Interpreter with IP Address Argument Undefined Elastic TOML
Curl to Telegram API Undefined Elastic TOML
Egress Network Connection Followed by Command Execution Undefined Elastic TOML
Egress Network Connection from Node.js Descendant Undefined Elastic TOML
File Download from Suspicious Top Level Domain Undefined Elastic TOML
Hidden Process Execution followed by Network Connection Undefined Elastic TOML
Python Network Connection Followed by Command Execution Undefined Elastic TOML
Suspicious Hidden Executable and Immediate Network Connection Undefined Elastic TOML
Suspicious Network Connection via Installer Package Undefined Elastic TOML
Suspicious Terraform Provider Execution and Network Connection Undefined Elastic TOML

+ 4 more from elastic/protections-artifacts → showing the 10 highest-severity

socfortress/Wazuh-Rules

6 rules
Detection Severity Format
Command to stop the cbdaemon service detected: systemctl stop cbdaemon.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl disable falcon-sensor or systemctl disable falcon-sensor.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl stop falcon-sensor or systemctl stop falcon-sensor.service High Wazuh XML
Powershell script: Network object creation detected High Wazuh XML
Use of curl with custom User-Agent (MITRE T1071.001 - C2 over HTTP) High Wazuh XML
Use of curl with custom User-Agent (MITRE T1071.001 - C2 over HTTP) - Exit Event High Wazuh XML

Azure/Azure-Sentinel

4 rules
Detection Severity Format
RunningRAT request parameters High KQL
IP address of Windows host encoded in web request Medium KQL
Windows host username encoded in base64 web request Medium KQL
FireEye stolen red teaming tools communications Undefined KQL

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Potential Beaconing Activity Undefined KQL

chronicle/detection-rules

2 rules
Detection Severity Format
emotet_through_word_document_sysmon_behavior Undefined YARA-L
solarwinds_backdoor_c2_host_name_detected_via_dns Undefined YARA-L

Wazuh Core Ruleset

1 rule
Detection Severity Format
PHP web attack. Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.