Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Command and Control

T1071.001 Web Protocols

Sub-technique of T1071 Application Layer Protocol

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation:…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 39.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.