T1583.006 — Web Services
T1583.006: Web Services
MITRE ATT&CK® Enterprise technique
| Tactics | Resource Development |
| Platforms | PRE |
| Permissions required | — |
| Version | 1.3 |
| Parent technique | T1583 |
Description
Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: FireEye APT29)(Citation: Hacker News GitHub Abuse 2024) By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1583/006
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/