{"id":"T1102","name":"Web Service","url":"https://attack.mitre.org/techniques/T1102","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0425","stix_id":"x-mitre-detection-strategy--769615c5-08d5-4f51-8f3b-7ac2f1febce8","name":"Suspicious Use of Web Services for C2","url":"https://attack.mitre.org/detectionstrategies/DET0425","analytics":[{"id":"AN1189","stix_id":"x-mitre-analytic--5a10a19a-035e-469e-8ec5-fafb1f0f0fe6","name":"Analytic 1189","description":"Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0425#AN1189","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"SSL/TLS Inspection or PCAP","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProcessName","description":"To tune for unexpected or uncommon executables initiating network connections"},{"field":"DataTransferThreshold","description":"Volume of outbound data in short time window (e.g., >1MB in <5 min)"},{"field":"TimeWindow","description":"Look for connections persisting outside of normal business hours"}],"live":true,"detection_strategies":["DET0425"],"techniques":["T1102"]},{"id":"AN1190","stix_id":"x-mitre-analytic--6e053521-1d6d-493f-8cd5-34f9a5992fc7","name":"Analytic 1190","description":"Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.","url":"https://attack.mitre.org/detectionstrategies/DET0425#AN1190","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"connect/sendto","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"conn.log, ssl.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ParentProcess","description":"Unusual parent-child process behavior initiating external comms (e.g., bash > curl)"},{"field":"HostnamePattern","description":"Destination hostnames (e.g., *.dropboxapi.com, *.graph.microsoft.com)"},{"field":"RequestFrequency","description":"Repeated requests at unusual intervals, suggesting beaconing"}],"live":true,"detection_strategies":["DET0425"],"techniques":["T1102"]},{"id":"AN1191","stix_id":"x-mitre-analytic--aff88199-cad0-47f8-b065-0ad7a86ec8a7","name":"Analytic 1191","description":"Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.","url":"https://attack.mitre.org/detectionstrategies/DET0425#AN1191","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process + network activity","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events, socket_events","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ProcessSignature","description":"Unsigned or user-modified apps communicating with cloud services"},{"field":"ConnectionInterval","description":"Beacon-like pattern of regular outbound communication"}],"live":true,"detection_strategies":["DET0425"],"techniques":["T1102"]},{"id":"AN1192","stix_id":"x-mitre-analytic--900bc498-4b81-43b6-bec2-3b55edc5c0ff","name":"Analytic 1192","description":"Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification.","url":"https://attack.mitre.org/detectionstrategies/DET0425#AN1192","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"network activity","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"esxi-vmkernel"},{"name":"vpxd.log","channel":"API communication","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"vpxd-log"}],"mutable_elements":[{"field":"RemoteIPRange","description":"Filter to detect only external/public destinations"},{"field":"VMContext","description":"Exclude known backup or patch automation services"}],"live":true,"detection_strategies":["DET0425"],"techniques":["T1102"]}],"live":true,"version":"1.0","techniques":["T1102"]}],"sigma_rules":[{"id":"18249279-932f-45e2-b37a-8925f2597670","title":"Process Initiated Network Connection To Ngrok Domain","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-16","modified":"2025-07-30","description":"Detects an executable initiating a network connection to \"ngrok\" domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://ngrok.com/","https://ngrok.com/blog-post/new-ngrok-domains","https://www.virustotal.com/gui/file/cca0c1182ac114b44dc52dd2058fcd38611c20bb6b5ad84710681d38212f835a/","https://www.rnbo.gov.ua/files/2023_YEAR/CYBERCENTER/november/APT29%20attacks%20Embassies%20using%20CVE-2023-38831%20-%20report%20en.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok.yml","techniques":["T1567","T1572","T1102"],"cves":[]},{"id":"19bf6fdb-7721-4f3d-867f-53467f6a5db6","title":"Communication To Ngrok Tunneling Service - Linux","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":null,"description":"Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/linux/network_connection/net_connection_lnx_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"1d08ac94-400d-4469-a82f-daee9a908849","title":"Communication To Ngrok Tunneling Service Initiated","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":"2024-02-02","description":"Detects an executable initiating a network connection to \"ngrok\" tunneling domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7","title":"New Connection Initiated To Potential Dead Drop Resolver Domain","author":"Sorina Ionescu, X__Junior (Nextron Systems)","status":"test","level":"high","date":"2022-08-17","modified":"2026-03-29","description":"Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks.\nIn this context attackers leverage known websites such as \"facebook\", \"youtube\", etc. In order to pass through undetected.\n","references":["https://web.archive.org/web/20220830134315/https://content.fireeye.com/apt-41/rpt-apt41/","https://securelist.com/the-tetrade-brazilian-banking-malware/97779/","https://blog.bushidotoken.net/2021/04/dead-drop-resolvers-espionage-inspired.html","https://github.com/kleiton0x00/RedditC2","https://twitter.com/kleiton0x7e/status/1600567316810551296","https://www.linkedin.com/posts/kleiton-kurti_github-kleiton0x00redditc2-abusing-reddit-activity-7009939662462984192-5DbI/?originalSubdomain=al"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102","attack.t1102.001"],"path":"rules/windows/network_connection/net_connection_win_domain_dead_drop_resolvers.yml","techniques":["T1102","T1102.001"],"cves":[]},{"id":"3ab65069-d82a-4d44-a759-466661a082d1","title":"Communication To LocaltoNet Tunneling Service Initiated","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"5c80b618-0dbb-46e6-acbb-03d90bcb6d83","title":"Network Connection Initiated To AzureWebsites.NET By Non-Browser Process","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-06-24","modified":"2024-07-16","description":"Detects an initiated network connection by a non browser process on the system to \"azurewebsites.net\". The latter was often used by threat actors as a malware hosting and exfiltration site.\n","references":["https://www.sentinelone.com/labs/wip26-espionage-threat-actors-abuse-cloud-infrastructure-in-targeted-telco-attacks/","https://symantec-enterprise-blogs.security.com/threat-intelligence/harvester-new-apt-attacks-asia","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://intezer.com/blog/research/how-we-escaped-docker-in-azure-functions/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102","attack.t1102.001"],"path":"rules/windows/network_connection/net_connection_win_domain_azurewebsites.yml","techniques":["T1102","T1102.001"],"cves":[]},{"id":"7050bba1-1aed-454e-8f73-3f46f09ce56a","title":"Cloudflared Tunnel Connections Cleanup","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-21","description":"Detects execution of the \"cloudflared\" tool with the tunnel \"cleanup\" flag in order to cleanup tunnel connections.","references":["https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_cleanup.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"7e9cf7b6-e827-11ed-a05b-0242ac120003","title":"Suspicious Non-Browser Network Communication With Google API","author":"Gavin Knapp","status":"experimental","level":"medium","date":"2023-05-01","modified":"2025-02-22","description":"Detects a non-browser process interacting with the Google API which could indicate the use of a covert C2 such as Google Sheet C2 (GC2-sheet)\n","references":["https://github.com/looCiprian/GC2-sheet","https://youtu.be/n2dFlSaBBKo","https://services.google.com/fh/files/blogs/gcat_threathorizons_full_apr2023.pdf","https://www.tanium.com/blog/apt41-deploys-google-gc2-for-attacks-cyber-threat-intelligence-roundup/","https://www.bleepingcomputer.com/news/security/hackers-abuse-google-command-and-control-red-team-tool-in-attacks/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_google_api_non_browser_access.yml","techniques":["T1102"],"cves":[]},{"id":"7e9cf7b6-e827-11ed-a05b-15959c120003","title":"Potentially Suspicious Network Connection To Notion API","author":"Gavin Knapp","status":"test","level":"low","date":"2023-05-03","modified":null,"description":"Detects a non-browser process communicating with the Notion API. This could indicate potential use of a covert C2 channel such as \"OffensiveNotion C2\"","references":["https://github.com/mttaggart/OffensiveNotion","https://medium.com/@huskyhacks.mk/we-put-a-c2-in-your-notetaking-app-offensivenotion-3e933bace332"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_notion_api_susp_communication.yml","techniques":["T1102"],"cves":[]},{"id":"9a019ffc-3580-4c9d-8d87-079f7e8d3fd4","title":"Cloudflared Tunnel Execution","author":"Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-17","modified":"2023-12-20","description":"Detects execution of the \"cloudflared\" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.","references":["https://blog.reconinfosec.com/emergence-of-akira-ransomware-group","https://github.com/cloudflare/cloudflared","https://developers.cloudflare.com/cloudflare-one/connections/connect-apps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102","attack.t1090","attack.t1572"],"path":"rules/windows/process_creation/proc_creation_win_cloudflared_tunnel_run.yml","techniques":["T1102","T1090","T1572"],"cves":[]},{"id":"c3dbbc9f-ef1d-470a-a90a-d343448d5875","title":"Suspicious Non-Browser Network Communication With Telegram API","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-19","modified":null,"description":"Detects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/small-sieve/NCSC-MAR-Small-Sieve.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.exfiltration","attack.t1102","attack.t1567","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_domain_telegram_api_non_browser_access.yml","techniques":["T1102","T1567","T1105"],"cves":[]},{"id":"c4568f5d-131f-4e78-83d4-45b2da0ec4f1","title":"Communication To LocaltoNet Tunneling Service Initiated - Linux","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2024-06-17","modified":null,"description":"Detects an executable initiating a network connection to \"LocaltoNet\" tunneling sub-domains.\nLocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.\nAttackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.\n","references":["https://localtonet.com/documents/supported-tunnels","https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.t1090","attack.t1102"],"path":"rules/linux/network_connection/net_connection_lnx_domain_localtonet_tunnel.yml","techniques":["T1572","T1090","T1102"],"cves":[]},{"id":"cea2b7ea-792b-405f-95a1-b903ea06458f","title":"Suspicious Child Process Of Manage Engine ServiceDesk","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2023-01-18","modified":"2023-08-29","description":"Detects suspicious child processes of the \"Manage Engine ServiceDesk Plus\" Java web service","references":["https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/","https://github.com/horizon3ai/CVE-2022-47966/blob/3a51c6b72ebbd87392babd955a8fbeaee2090b35/CVE-2022-47966.py","https://blog.viettelcybersecurity.com/saml-show-stopper/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102"],"path":"rules/windows/process_creation/proc_creation_win_java_manageengine_susp_child_process.yml","techniques":["T1102"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}