FORENSIA

ATT&CK · T1071.001 · sub-technique

Web Protocols

Tactics: command-and-control

About

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsParent: T1071 Application Layer ProtocolMITRE ATT&CK ↗

Used by actors

57 known groups

Software

341 malware/tools implement this

RIPTIDEHikitTaidoorPlugXIxesheReginChina ChopperUroburosCHOPSTICKDyreCarbanakBACKSPACENETEAGLEHAMMERTOSSLOWBALLBUBBLEWRAPJHUHUGITADVSTORESHELLCozyCarPinchDukeGeminiDukeCosmicDukeMiniDukeOnionDukeSeaDukeCloudDukeWinMMSys10DustySkyELMER4H RAT3PARA RATpngdownerhttpclientHTTPBrowserOwaAuthSakulaPsyloEliseEmissaryMis-TypeS-TypeZLibHi-ZorBlackEnergyEpicTrojan.KaraganyCrimsonRemsecComRATBBSRATBADNEWSCORESHELLOLDBAITShamoonWinnti for WindowsChChesPteranodonRTMRedLeavesCobalt StrikeSNUGRIDEKomplexGazerHelminthFelismusReaverPOWRUNERDownPaperDaserfPupyPUNCHBUGGYNETWIREDipsindVasportSmoke LoaderZeroTGravityRATProxysvcBankshotROKRATRATANKBADealersChoiceComnieGold DragonKoadicZebrocyVERMINRGDoorInvisiMoleOopsIEKazuarTrickBotFELIXROOTBisonalQUADAGENTUPPERCUTKeydnapMacSpyMore_eggsZeus PandaAgent TeslaUBoatRATDarkCometCarbonBadPatchMicropsiaOctopusXbashGreyEnergySeasaltCardinal RATOSX_OCEANLOTUS.DNOKKIFinal1stspyKONNIEmpireEmotetPOWERTONSpeakUpRemexiPoshC2FlawedAmmyyServHelperDridexnjRATUrsnifYAHOYAHHAWKBALLEvilBunnyHyperBroExaramel for LinuxMacheteZxShellPoetRATWinnti for LinuxPLEADTSCookieOkrumPowerShowerVBShowerShimRatShimRatReporterLokibotRising SunMazePonyMetamorfoAria-bodyRamsayMechaFlounderGet2WindTailABKBBKdown_newAvengerBackConfigValakGoopyBundloreIcedIDCarberpStrongPityGoldenSpyRDATREvilDaclsMCMDDrovorubAnchorFatDukeLiteDukeWellMessSoreFangPolyglotDukeBLINDINGCANKGH_SPYCSPY DownloaderGrandoreiroSLOTHFULMEDIABazarCrutchSparkEgregorSUNBURSTGuLoaderBlackMouldExplosiveSUPERNOVALookBackAppleJeusGoldMaxSibotOut1ThiefQuestShadowPadGoldFinderP.A.S. WebshellKinsingDokiStuxnetIndustroyerSideTwistDEATHRANSOMAppleSeedRainyDayChaesGrimAgentSliverBoomBoxVaporRagePeppyTurianSMOKEDHAMQakBotMarkiRATxCaonBLUELIGHTDiavolClamblingFoggyWebRCSessionPandoraGelsemiumTinyTurlaTomirisDarkWatchmanCharmPowerTorismaLitePowerTrailBlazerQuietSieveCyclops BlinkWhisperGateNeoichorDRATzarusDonutFlagproMythicDanBotMilanOutSteelSaint BotSharkKevinIceAppleCreepyDriveCreepySnailAmadeyMongallAction RATAuTo StealerSquirrelwafflePingPullSmall SieveSTARWHALESUGARDUMPPowGoopMoriPcShareKEYPLUGmetaMainMafaldaBrute Ratel C4SVCReadyWoody RATDarkTortillaANDROMEDAKOPILUWAKQUIETCANARYBADHATCHSamuraiNinjaCOATHANGERNGLitePULSECHECKSLIGHTPULSESTEADYPULSEWIREFIRELIGHTWIREFRAMESTINGRaspberry RobinIPsec HelperLunarWebFRPRaccoon StealerCHIMNEYSWEEPCuckoo StealerCovenantManjusakaLatrodectusSnappyTCPSampleCheck5000MangoOilBoosterShrinkLockerMagicRATStrelaStealerBOLDMOVELightSpyLine DancerreGeorgLine RunnerNeo-reGeorgKapekaNICECURLTAMECATTroll StealerGomirStealBitTRANSLATEXTLockBit 3.0XLoaderQuick AssistSagerunexLumma StealerMOPSLEDRIFLESPINETHINCRUSTBOOKWORMPUBLOADHavocTONESHELLRedLine StealerInvisibleFerretBeaverTailXORIndex LoaderHexEval Loaderevilginx2HTTPTroyShai-HuludGlassWormBRICKSTORMPHPsertIronWindAshTagMuddyViperTsundere BotnetLAMEHUGRustyWater

Corpus indicators tagged with this technique

7,988 indicators in the corpus carry T1071.001.

IndicatorTypeFamilySevSrc
cve-2020-22658cve852
cve-2025-34085cve851
cve-2025-68670cve852
cve-2020-22653cve852
cve-2021-25646cve851
cve-2025-12057cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2013-7471cve851
cve-2026-0740cve851
cve-2026-3844cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-15047cve854
cve-2025-34054cve854
cve-2026-3102cve853
cve-2021-4045cve851
cve-2016-5681cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2017-18377cve851
cve-2021-29441cve851
cve-2026-1969cve851
cve-2025-23304cve852
cve-2025-7443cve851

Showing the top 30 by severity of 7,988.