Cross-source coverage

T1071.001 / ATT&CK

Application Layer Protocol: Web Protocols

115 rules across 8 sources.

4 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
NSM:FlowWinEventLog:Sysmonauditd:SYSCALLmacos:osquerymacos:unifiedlogesxi:shell

How MITRE says to detect it DET0027

Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Windows Analytic 0075

Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.

  • NSM:Flow http.log, ssl.log
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0076

Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.

  • NSM:Flow http.log, conn.log
  • auditd:SYSCALL execve

macOS Analytic 0077

Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields).

  • macos:osquery socket_events
  • macos:unifiedlog log stream --predicate

ESXi Analytic 0078

Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.

  • NSM:Flow SPAN or port-mirrored HTTP/S
  • esxi:shell /root/.ash_history or /etc/init.d/*

Network Devices Analytic 0079

Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.

  • NSM:Flow http.log, ssl.log, websocket.log

SigmaHQ/sigma

42 rules
Detection Severity Format
HackTool - BabyShark Agent Default URL Pattern Critical Sigma
PwnDrp Access Critical Sigma
Ursnif Malware C2 URL Pattern Critical Sigma
APT40 Dropbox Tool User Agent High Sigma
APT User Agent High Sigma
Axios NPM Compromise Malicious C2 Domain DNS Query High Sigma
Bitsadmin to Uncommon IP Server Address High Sigma
Bitsadmin to Uncommon TLD High Sigma
Chafer Malware URL Pattern High Sigma
ComRAT Network Communication High Sigma

+ 32 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

29 rules
Detection Severity Format
Cobalt Strike Command and Control Beacon High Elastic TOML
Default Cobalt Strike Team Server Certificate High Elastic TOML
Halfbaked Command and Control Beacon High Elastic TOML
Outlook Home Page Registry Modification High Elastic TOML
Possible FIN7 DGA Command and Control Behavior High Elastic TOML
Suspicious Curl from macOS Application High Elastic TOML
Suspicious Curl to Google App Script Endpoint High Elastic TOML
Suspicious Execution from a WebDav Share High Elastic TOML
Curl or Wget Spawned via Node.js Medium Elastic TOML
Execution via OpenClaw Agent Medium Elastic TOML

+ 19 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

15 rules
Detection Severity Format
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Undefined SPL
Cisco Secure Firewall - Connection to File Sharing Domain Undefined SPL
Cisco Secure Firewall - High EVE Threat Confidence Undefined SPL
Cisco Secure Firewall - Wget or Curl Download Undefined SPL
HTTP C2 Framework User Agent Undefined SPL
HTTP Duplicated Header Undefined SPL
HTTP Malware User Agent Undefined SPL
HTTP Possible Request Smuggling Undefined SPL
HTTP PUA User Agent Undefined SPL
HTTP Rapid POST with Mixed Status Codes Undefined SPL

+ 5 more from splunk/security_content → showing the 10 highest-severity

elastic/protections-artifacts

14 rules
Detection Severity Format
Command Interpreter with IP Address Argument Undefined Elastic TOML
Curl to Telegram API Undefined Elastic TOML
Egress Network Connection Followed by Command Execution Undefined Elastic TOML
Egress Network Connection from Node.js Descendant Undefined Elastic TOML
File Download from Suspicious Top Level Domain Undefined Elastic TOML
Hidden Process Execution followed by Network Connection Undefined Elastic TOML
Python Network Connection Followed by Command Execution Undefined Elastic TOML
Suspicious Hidden Executable and Immediate Network Connection Undefined Elastic TOML
Suspicious Network Connection via Installer Package Undefined Elastic TOML
Suspicious Terraform Provider Execution and Network Connection Undefined Elastic TOML

+ 4 more from elastic/protections-artifacts → showing the 10 highest-severity

socfortress/Wazuh-Rules

6 rules
Detection Severity Format
Command to stop the cbdaemon service detected: systemctl stop cbdaemon.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl disable falcon-sensor or systemctl disable falcon-sensor.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl stop falcon-sensor or systemctl stop falcon-sensor.service High Wazuh XML
Powershell script: Network object creation detected High Wazuh XML
Use of curl with custom User-Agent (MITRE T1071.001 - C2 over HTTP) High Wazuh XML
Use of curl with custom User-Agent (MITRE T1071.001 - C2 over HTTP) - Exit Event High Wazuh XML

Azure/Azure-Sentinel

5 rules
Detection Severity Format
RunningRAT request parameters High KQL
Discord CDN Risky File Download (ASIM Web Session Schema) Medium KQL
IP address of Windows host encoded in web request Medium KQL
Windows host username encoded in base64 web request Medium KQL
FireEye stolen red teaming tools communications Undefined KQL

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Potential Beaconing Activity Undefined KQL
Threat Hunting for telegram as a Commmand & Control channel Undefined KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
PHP web attack. Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.