Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1102

T1102Web Service

T1102 — Web Service is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 15 detection use cases covering it and 12 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
12Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (15)

Linux Ngrok Reverse Proxy Usage ESCU actions · hunting P Windows Ngrok Reverse Proxy Usage ESCU actions · hunting P Ngrok Reverse Proxy on Network ESCU actions · hunting P Windows Abused Web Services ESCU actions · hunting P [LLM] Outbound traffic to known AI token-jacking transfer-station infrastructure (Unit42 IPs) Bespoke c2 · hunting DSΣPDDCSCW [LLM] Bun runtime fetched from oven-sh GitHub releases during npm install Bespoke c2 · hunting DSPCS [LLM] Endpoint egress/DNS to UAT-11764 / ARToken IOC infrastructure Bespoke c2 · alerting DSΣDDCS [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev Bespoke c2 · hunting DSΣPDDCS [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS [LLM] Node.js resolving Miasma fallback C2 channels (BitTorrent DHT / Nostr relays) Bespoke c2 · alerting DSΣPDDCS [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence Bespoke install · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] Browser load of Beamglea redirect-* or mad-* package script from unpkg.com Bespoke exploit · alerting DSΣPDDCS [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) Bespoke actions · hunting DSPDDCS [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.ua Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (12)