1200KM / simulation
T1071.001 Web Protocols — Attack Simulation
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and…
Technique description
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Malicious User Agents - Nix
Procedure 2d7c471a-e887-4b78-b0dc-b0df1f2e0658; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Malicious User Agents - Powershell
Procedure 81c13829-f6c9-45b8-85a6-053366d55297; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Malicious User Agents - CMD
Procedure dc3488b0-08c7-4fea-b585-905c83b48180; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Stealth Falcon · G0038
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- Orangeworm · G0071
- APT19 · G0073
- Rancor · G0075
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- SilverTerrier · G0083
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Wizard Spider · G0102
- Rocke · G0106
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- TA551 · G0127
- Mustang Panda · G0129
- TeamTNT · G0139
- Confucius · G0142
- BITTER · G1002
- Metador · G1013
- LuminousMoth · G1014
- FIN13 · G1016
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- Sea Turtle · G1041
- RedEcho · G1042
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.