Web Service T1102

Tactic: Command & Control

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Events covered

20 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 72 rules share fields, values, and exclusions.

Fields filtered most (73 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name27in 11, eq 9, starts_with 6, wildcard 5, is_not_null 3, contains 2, ne 1bash, busybox, node, .*, python
EventType20eq 15, in 4, ne 1exec, lookup_result, start, exec_event, ProcessRollup2
DestinationHostname18contains 8, ends_with 7, starts_with 2, wildcard 2, eq 1, in 1, is_not_null 1, is_null 1.localto.net, .localtonet.com, tunnel.ap.ngrok.com, tunnel.au.ngrok.com, tunnel.eu.ngrok.com
Image16ends_with 8, wildcard 8, eq 5, starts_with 5, contains 3, is_null 3./*, /boot/*, /dev/shm/*, \appdata\local\discord\, \appdata\local\flock\
QueryName16wildcard 7, is_not_null 6, ends_with 4, in 2, contains 1, ne 1*.4shared.com, *.aternos.me, *.geojs.io, *.2miners.com, *.antpool.com
event.type14eq 14start, creation
host.os.type13eq 11, in 2
CommandLine10contains 8, in 2 tunnel , *--config*, *authtoken*, *http*, -config
Initiated5eq 5true
DvcAction3eq 1, in 1, starts_with 11, 3, BLOCK_, none
EventID3eq 322, 4688
OriginalFileName3eq 3bitsadmin.exe, certutil.exe, cmstp.exe, cscript.exe, installutil.exe
event.category3eq 3network, process
process.args3eq 3--endpoint-url, -clsid:{0002df01-0000-0000-c000-000000000046}, tunnel
CurrentDirectory2starts_with 1, wildcard 1/boot, /boot*, /dev/shm, /dev/shm*, /home/*/*

Top indicator values (1601 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
131078
process_namein
curl
889
process_namein
bash
7202
process_namein
sh
7197
process_namein
wget
746
process_namein
zsh
7196
process_namein
busybox
668
process_namein
csh
6159
process_namein
dash
6170
process_namein
env
617
process_namein
fish
6163
process_namein
ksh
6163
process_namein
tcsh
6156
process_namein
timeout
615
Imagewildcard
/tmp/*
733
Imagewildcard
/var/tmp/*
731
Imagewildcard
./*
617
Imagewildcard
/boot/*
621
Imagewildcard
/dev/shm/*
629
Imagewildcard
/home/*/*
623
Imagewildcard
/lost+found/*
610
Imagewildcard
/proc/*
610
Imagewildcard
/root/*
613
Imagewildcard
/run/*
617
Imagewildcard
/sys/*
610
Imagewildcard
/var/mail/*
610
Imagewildcard
/var/run/*
611
Imagewildcard
/var/www/*
613
EventTypeeq
exec
6576
EventTypeeq
lookup_result
69

Exclusions (496 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imageends_with
\brave.exe
5
Imageends_with
\maxthon.exe
5
Imageends_with
\msedge.exe
5
Imageends_with
\msedgewebview2.exe
5
Imageends_with
\opera.exe
5
Imageends_with
\safari.exe
5
Imageends_with
\seamonkey.exe
5
Imageends_with
\vivaldi.exe
5
Imageends_with
\whale.exe
5
Imageends_with
\windowsapps\microsoftedge.exe
5
process.code_signature.trustedeq
true
5
Imageeq
c:\program files (x86)\google\chrome\application\chrome.exe
4
Imageeq
c:\program files (x86)\internet explorer\iexplore.exe
4
Imageeq
c:\program files (x86)\microsoft\edge\application\msedge.exe
4
Imageeq
c:\program files (x86)\mozilla firefox\firefox.exe
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 19 rules

Elastic 30 rules

Splunk 6 rules

Kusto 17 rules