Umbra Wiki technique technique/T1583.006
Back to wiki

T1583.006 — Web Services

provenance: imported · ATT&CK: T1583.006

T1583.006: Web Services

MITRE ATT&CK® Enterprise technique

Tactics Resource Development
Platforms PRE
Permissions required
Version 1.3
Parent technique T1583

Description

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: FireEye APT29)(Citation: Hacker News GitHub Abuse 2024) By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1583/006
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/