Loading interactive filters…
1200KM / detection
T1102 Web Service — Detection Rules
Detection workspace for T1102 Web Service: 13 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- Communication To LocaltoNet Tunneling Service Initiated - Linux · test · high · {"category":"network_connection","product":"linux"}
- Communication To Ngrok Tunneling Service - Linux · test · high · {"product":"linux","category":"network_connection"}
- Network Connection Initiated To AzureWebsites.NET By Non-Browser Process · test · medium · {"category":"network_connection","product":"windows"}
- New Connection Initiated To Potential Dead Drop Resolver Domain · test · high · {"category":"network_connection","product":"windows"}
- Suspicious Non-Browser Network Communication With Google API · experimental · medium · {"product":"windows","category":"network_connection"}
- Communication To LocaltoNet Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Process Initiated Network Connection To Ngrok Domain · test · high · {"category":"network_connection","product":"windows"}
- Communication To Ngrok Tunneling Service Initiated · test · high · {"category":"network_connection","product":"windows"}
- Potentially Suspicious Network Connection To Notion API · test · low · {"product":"windows","category":"network_connection"}
- Suspicious Non-Browser Network Communication With Telegram API · test · medium · {"product":"windows","category":"network_connection"}
- Cloudflared Tunnel Connections Cleanup · test · medium · {"category":"process_creation","product":"windows"}
- Cloudflared Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Child Process Of Manage Engine ServiceDesk · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1102 Web Service
MATCH(connection_to_disallowed_web_service_category OR known_c2_account_or_url) -> ALERT
Anomaly models
Web or collaboration service used as control channel — T1102 Web Service
Comparison unit: process-user-service relationship.
Expected behavior: approved processes and users access a known service set.
Deviation: new relationship, unusual service category, or repeated low-volume sequence.
ATT&CK analytic guidance
Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.
Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.
Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.
Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.