MITRE ATT&CK sub-technique
T1071.001 — Web Protocols
Last fetched
T1071.001 (Web Protocols) is a MITRE ATT&CK sub-technique tracked in WhisperGraph, serving the Command and Control tactic.
Description
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
Tactics
Related techniques
Parent technique: T1071 · Application Layer Protocol
Threat actors observed using this technique
- LuminousMoth
- APT41
- APT42
- Rancor
- Wizard Spider
- Metador
- BlackByte
- FIN13
- Medusa Group
- Ke3chang
- BRONZE BUTLER
- Inception
- Gamaredon Group
- Threat Group-3390
- Cobalt Group
- Higaisa
- TA505
- Stealth Falcon
- Mustang Panda
- BITTER
- Confucius
- Lazarus Group
- SilverTerrier
- RedCurl
- HAFNIUM
- Chimera
- Dark Caracal
- Moonstone Sleet
- Windshift
- Winter Vivern
- TA551
- Sidewinder
- APT19
- APT18
- Sea Turtle
- Daggerfly
- FIN8
- RedEcho
- Tropic Trooper
- FIN4
- TeamTNT
- OilRig
- Kimsuky
- Rocke
- VOID MANTICORE
- APT28
- Magic Hound
- Orangeworm
- APT32
- APT33
- Sandworm Team
- APT37
- APT38
- APT39
- WIRTE
- MuddyWater
- Turla
- WIZARD SPIDER
- WindShift
- MUSTANG PANDA
- Void Manticore
- RANCOR
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1071.001 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.