Cross-source coverage

T1102 / ATT&CK

Web Service

323 rules · 319 families across 9 sources.

Showing deprecated and atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).

Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SysmonNSM:Flowauditd:SYSCALLmacos:unifiedlogmacos:osqueryesxi:vmkernelvpxd.log

How MITRE says to detect it DET0425

Suspicious Use of Web Services for C2

Windows Analytic 1189

Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.

  • WinEventLog:Sysmon EventCode=3, 22
  • NSM:Flow SSL/TLS Inspection or PCAP

Linux Analytic 1190

Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.

  • auditd:SYSCALL connect/sendto
  • NSM:Flow conn.log, ssl.log

macOS Analytic 1191

Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.

  • macos:unifiedlog process + network activity
  • macos:osquery process_events, socket_events

ESXi Analytic 1192

Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification.

  • esxi:vmkernel network activity
  • vpxd.log API communication

Sub-techniques with coverage

Counted in the 323 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

257 rules · 253 families
Detection Severity Format
ET EXPLOIT_KIT Observed ClickFix Domain (authentication-to .help) in DNS Lookup High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (authentication-to .help) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (connection .click) in DNS Lookup High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (connection .click) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (deliveryoka .com) in DNS Lookup High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (deliveryoka .com) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (fowlerkiawindsor .com) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (genesisofkennesaw .com) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (gilchristautomotive .com) in TLS SNI High Suricata
ET EXPLOIT_KIT Observed ClickFix Domain (hep2go .com) in TLS SNI High Suricata

+ 247 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

19 rules
Detection Severity Format
PwnDrp Access Critical Sigma
Communication To LocaltoNet Tunneling Service Initiated High Sigma
Communication To LocaltoNet Tunneling Service Initiated - Linux High Sigma
Communication To Ngrok Tunneling Service Initiated High Sigma
Communication To Ngrok Tunneling Service - Linux High Sigma
New Connection Initiated To Potential Dead Drop Resolver Domain High Sigma
Process Initiated Network Connection To Ngrok Domain High Sigma
Raw Paste Service Access High Sigma
Suspicious Child Process Of Manage Engine ServiceDesk High Sigma
Cloudflared Tunnel Connections Cleanup Medium Sigma

+ 9 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

18 rules
Detection Severity Format
AWS SNS Topic Message Publish by Rare User High Elastic TOML
Google Calendar C2 via Script Interpreter High Elastic TOML
Network Connection to OAST Domain via Script Interpreter High Elastic TOML
Potential Etherhiding C2 via Blockchain Connection High Elastic TOML
Suspicious Curl to Google App Script Endpoint High Elastic TOML
AWS CLI Command with Custom Endpoint URL Medium Elastic TOML
Connection to Common Large Language Model Endpoints Medium Elastic TOML
Linux Telegram API Request Medium Elastic TOML
Suspicious AWS S3 Connection via Script Interpreter Medium Elastic TOML
Suspicious File Downloaded from Google Drive Medium Elastic TOML

+ 8 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

11 rules
Detection Severity Format
Attempt to establish VScode Remote Tunnel Undefined Elastic TOML
Connection to WebService by an Unsigned Binary Undefined Elastic TOML
Connection to WebService by a Signed Binary Proxy Undefined Elastic TOML
DNS Request by Recently Created Executable Undefined Elastic TOML
DNS Request to Crypto/DHT Services Undefined Elastic TOML
DNS Request to Crypto Miner Service Undefined Elastic TOML
DNS Request to Dynamic DNS via Suspicious Executable Undefined Elastic TOML
DNS Request to IP Lookup Service from Suspicious Working Directory Undefined Elastic TOML
DNS Request to Suspicious File Upload/Download Service Undefined Elastic TOML
Potential VScode Remote Tunnel Established Undefined Elastic TOML

+ 1 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

6 rules
Detection Severity Format
Linux Ngrok Reverse Proxy Usage Undefined SPL
Ngrok Reverse Proxy on Network Undefined SPL
Potential Telegram API Request Via CommandLine Undefined SPL
Windows Abused Web Services Undefined SPL
Windows DNS Query Request by Telegram Bot API Undefined SPL
Windows Ngrok Reverse Proxy Usage Undefined SPL

Wazuh Core Ruleset

5 rules
Detection Severity Format
A connection to cloud resource was started by · win.eventdata.commandLine = (?i)(live|outlook|google|drive|microsoft|dropbox) High Wazuh XML
Apache: Client sent malformed Host header. Possible Code Red attack. Medium Wazuh XML
Apache: Code Red attack. Medium Wazuh XML
FortiAuth: Authentication failed by user . · data.status = Failed Medium Wazuh XML
ownCloud possible malicious request. Medium Wazuh XML

Azure/Azure-Sentinel

4 rules
Detection Severity Format
CreepyDrive request URL sequence High KQL
CreepyDrive URLs High KQL
A host is potentially running a hacking tool (ASIM Web Session schema) Medium KQL
Discord download invoked from cmd line (ASIM Version) Undefined KQL

chronicle/detection-rules

2 rules
Detection Severity Format
cobaltstrike_malleable_ocsp_profile Undefined YARA-L
cobaltstrike_malleable_onedrive_browsing_traffic_profile Undefined YARA-L

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
Sysmon - Event 3: Network connection by · Web Service (T1102) Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.