T1071.001 Web Protocols
Sub-technique of T1071 Application Layer Protocol
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation:…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- HackTool - BabyShark Agent Default URL Patterncriticaltest · proxy
- PwnDrp Accesscriticaltest · proxy
- Ursnif Malware Download URL Patternhighstable · proxy
- APT User Agenthightest · proxy
- APT40 Dropbox Tool User Agenthightest · proxy
- Bitsadmin to Uncommon IP Server Addresshightest · proxy
- Bitsadmin to Uncommon TLDhightest · proxy
- Chafer Malware URL Patternhightest · proxy
- ComRAT Network Communicationhightest · proxy
- Crypto Miner User Agenthightest · proxy
- Exploit Framework User Agenthightest · proxy
- HackTool - CobaltStrike Malleable Profile Patterns - Proxyhightest · proxy
- HackTool - Empire UserAgent URI Combohightest · proxy
- Malware User Agenthightest · proxy
- Outbound Network Connection Initiated By Microsoft Dialerhightest · windows
- Raw Paste Service Accesshightest · proxy
- Renamed Visual Studio Code Tunnel Executionhightest · windows
- Suspicious User Agenthightest · proxy
- Wannacry Killswitch Domainhightest · dns
- Windows WebDAV User Agenthightest · proxy
- Axios NPM Compromise Malicious C2 Domain DNS Queryhighexperimental · dns
- Kalambur Backdoor Curl TOR SOCKS Proxy Executionhighexperimental · windows
- Katz Stealer Suspicious User-Agenthighexperimental · zeek
- Change User Agents with WebRequestmediumtest · windows
Showing 25 of 39.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.