1200KM / detection
T1071.001 Web Protocols — Detection Rules
Detection workspace for T1071.001 Web Protocols: 31 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Curl Change User Agents - Linux · test · medium · {"category":"process_creation","product":"linux"}
- Suspicious Installer Package Child Process · test · medium · {"category":"process_creation","product":"macos"}
- Wannacry Killswitch Domain · test · high · {"category":"dns"}
- Windows WebDAV User Agent · test · high · {"category":"proxy"}
- HackTool - BabyShark Agent Default URL Pattern · test · critical · {"category":"proxy"}
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy · test · high · {"category":"proxy"}
- HackTool - Empire UserAgent URI Combo · test · high · {"category":"proxy"}
- PwnDrp Access · test · critical · {"category":"proxy"}
- Raw Paste Service Access · test · high · {"category":"proxy"}
- Telegram API Access · test · medium · {"category":"proxy"}
- APT User Agent · test · high · {"category":"proxy"}
- Suspicious Base64 Encoded User-Agent · test · medium · {"category":"proxy"}
- Bitsadmin to Uncommon IP Server Address · test · high · {"category":"proxy"}
- Bitsadmin to Uncommon TLD · test · high · {"category":"proxy"}
- Crypto Miner User Agent · test · high · {"category":"proxy"}
- HTTP Request With Empty User Agent · test · medium · {"category":"proxy"}
- Exploit Framework User Agent · test · high · {"category":"proxy"}
- Malware User Agent · test · high · {"category":"proxy"}
- Windows PowerShell User Agent · test · medium · {"category":"proxy"}
- Suspicious User Agent · test · high · {"category":"proxy"}
- Potential Base64 Encoded User-Agent · test · medium · {"category":"proxy"}
- Cloudflared Tunnels Related DNS Requests · test · medium · {"category":"dns_query","product":"windows"}
- DNS Query To Devtunnels Domain · test · medium · {"category":"dns_query","product":"windows"}
- DNS Query Request By QuickAssist.EXE · experimental · low · {"category":"dns_query","product":"windows"}
- DNS Query To Visual Studio Code Tunnels Domain · test · medium · {"product":"windows","category":"dns_query"}
- Outbound Network Connection Initiated By Microsoft Dialer · test · high · {"category":"network_connection","product":"windows"}
- Change User Agents with WebRequest · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Visual Studio Code Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- Visual Studio Code Tunnel Shell Execution · test · medium · {"category":"process_creation","product":"windows"}
- Renamed Visual Studio Code Tunnel Execution · test · high · {"category":"process_creation","product":"windows"}
- Visual Studio Code Tunnel Service Installation · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1071.001 Web Protocols
MATCH(destination_or_url IN denylist OR http_signature IN known_c2_patterns) -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
AN0075 Analytic 0075
Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.
AN0076 Analytic 0076
Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.
AN0077 Analytic 0077
Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields).
AN0078 Analytic 0078
Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.
AN0079 Analytic 0079
Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Stealth Falcon · G0038
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- Orangeworm · G0071
- APT19 · G0073
- Rancor · G0075
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- SilverTerrier · G0083
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Wizard Spider · G0102
- Rocke · G0106
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- TA551 · G0127
- Mustang Panda · G0129
- TeamTNT · G0139
- Confucius · G0142
- BITTER · G1002
- Metador · G1013
- LuminousMoth · G1014
- FIN13 · G1016
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- Sea Turtle · G1041
- RedEcho · G1042
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.