Cross-source coverage
T1102 / ATT&CK
Web Service
71 rules · 68 families across 8 sources.
5 deprecated hidden · include 233 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonNSM:Flowauditd:SYSCALLmacos:unifiedlogmacos:osqueryesxi:vmkernelvpxd.log
How MITRE says to detect it DET0425
Suspicious Use of Web Services for C2
Windows Analytic 1189
Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.
WinEventLog:SysmonEventCode=3, 22NSM:FlowSSL/TLS Inspection or PCAP
Linux Analytic 1190
Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.
auditd:SYSCALLconnect/sendtoNSM:Flowconn.log, ssl.log
macOS Analytic 1191
Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.
macos:unifiedlogprocess + network activitymacos:osqueryprocess_events, socket_events
ESXi Analytic 1192
Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification.
esxi:vmkernelnetwork activityvpxd.logAPI communication
Sub-techniques with coverage
Counted in the 71 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| AWS SNS Topic Message Publish by Rare User | High | Elastic TOML |
| Google Calendar C2 via Script Interpreter | High | Elastic TOML |
| Network Connection to OAST Domain via Script Interpreter | High | Elastic TOML |
| Potential Etherhiding C2 via Blockchain Connection | High | Elastic TOML |
| Suspicious Curl to Google App Script Endpoint | High | Elastic TOML |
| AWS CLI Command with Custom Endpoint URL | Medium | Elastic TOML |
| Connection to Common Large Language Model Endpoints | Medium | Elastic TOML |
| Linux Telegram API Request | Medium | Elastic TOML |
| Suspicious AWS S3 Connection via Script Interpreter | Medium | Elastic TOML |
| Suspicious File Downloaded from Google Drive | Medium | Elastic TOML |
+ 8 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
14 rules| Detection | Severity | Format |
|---|---|---|
| Communication To LocaltoNet Tunneling Service Initiated | High | Sigma |
| Communication To LocaltoNet Tunneling Service Initiated - Linux | High | Sigma |
| New Connection Initiated To Potential Dead Drop Resolver Domain | High | Sigma |
| Process Initiated Network Connection To Ngrok Domain | High | Sigma |
| Suspicious Child Process Of Manage Engine ServiceDesk | High | Sigma |
| Cloudflared Tunnel Connections Cleanup | Medium | Sigma |
| Cloudflared Tunnel Execution | Medium | Sigma |
| Github Self-Hosted Runner Execution | Medium | Sigma |
| Network Connection Initiated To AzureWebsites.NET By Non-Browser Process | Medium | Sigma |
| Potentially Suspicious Azure Front Door Connection | Medium | Sigma |
+ 4 more from SigmaHQ/sigma → showing the 10 highest-severity
Emerging Threats Open
12 rules · 9 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING Dotted Quad Host Workzueg HTTP Server String Response | High | Suricata |
| ET MALWARE GhostRedirector Rungan Backdoor Access M1 4 variants | High | Suricata |
| ET MALWARE GhostRedirector Rungan Backdoor Access M2 4 variants | High | Suricata |
| ET MALWARE GhostRedirector Rungan Backdoor Access M3 4 variants | High | Suricata |
| ET MALWARE GhostRedirector Rungan Backdoor Access M4 4 variants | High | Suricata |
| ET MALWARE KimJongRAT CnC Checkin | High | Suricata |
| ET INFO DNS Query for Webhook/HTTP Request Inspection Service (saucelabs .com) | Informational | Suricata |
| ET INFO Moltbook AI Agent Registration Attempt | Informational | Suricata |
| ET INFO Moltbook heartbeat.md request | Informational | Suricata |
| ET INFO Moltbook messaging.md request | Informational | Suricata |
+ 2 more from Emerging Threats Open → showing the 10 highest-severity
elastic/protections-artifacts
11 rules| Detection | Severity | Format |
|---|---|---|
| Attempt to establish VScode Remote Tunnel | Undefined | Elastic TOML |
| Connection to WebService by an Unsigned Binary | Undefined | Elastic TOML |
| Connection to WebService by a Signed Binary Proxy | Undefined | Elastic TOML |
| DNS Request by Recently Created Executable | Undefined | Elastic TOML |
| DNS Request to Crypto/DHT Services | Undefined | Elastic TOML |
| DNS Request to Crypto Miner Service | Undefined | Elastic TOML |
| DNS Request to Dynamic DNS via Suspicious Executable | Undefined | Elastic TOML |
| DNS Request to IP Lookup Service from Suspicious Working Directory | Undefined | Elastic TOML |
| DNS Request to Suspicious File Upload/Download Service | Undefined | Elastic TOML |
| Potential VScode Remote Tunnel Established | Undefined | Elastic TOML |
+ 1 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
6 rules| Detection | Severity | Format |
|---|---|---|
| Linux Ngrok Reverse Proxy Usage | Undefined | SPL |
| Ngrok Reverse Proxy on Network | Undefined | SPL |
| Potential Telegram API Request Via CommandLine | Undefined | SPL |
| Windows Abused Web Services | Undefined | SPL |
| Windows DNS Query Request by Telegram Bot API | Undefined | SPL |
| Windows Ngrok Reverse Proxy Usage | Undefined | SPL |
Wazuh Core Ruleset
5 rules| Detection | Severity | Format |
|---|---|---|
| A connection to cloud resource was started by · win.eventdata.commandLine = (?i)(live|outlook|google|drive|microsoft|dropbox) | High | Wazuh XML |
| Apache: Client sent malformed Host header. Possible Code Red attack. | Medium | Wazuh XML |
| Apache: Code Red attack. | Medium | Wazuh XML |
| FortiAuth: Authentication failed by user . · data.status = Failed | Medium | Wazuh XML |
| ownCloud possible malicious request. | Medium | Wazuh XML |
Azure/Azure-Sentinel
4 rules| Detection | Severity | Format |
|---|---|---|
| CreepyDrive request URL sequence | High | KQL |
| CreepyDrive URLs | High | KQL |
| A host is potentially running a hacking tool (ASIM Web Session schema) | Medium | KQL |
| Discord download invoked from cmd line (ASIM Version) | Undefined | KQL |
socfortress/Wazuh-Rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 3: Network connection by · Web Service (T1102) | Low | Wazuh XML |